vendor:
Sun Java JRE
by:
jduck
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Sun Java JRE
Affected Version From: 1.3.1_26
Affected Version To: 1.6.0_16
Patch Exists: YES
Related CWE: CVE-2009-3869
CPE: a:oracle:java:1.6.0_16
Metasploit:
https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2009-3869/, https://www.rapid7.com/db/vulnerabilities/vmsa-2010-0002-3-java-jre-security-update-cve-2009-3869/, https://www.rapid7.com/db/vulnerabilities/vmsa-2010-0005-cve-2009-3869/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2009-3869/, https://www.rapid7.com/db/vulnerabilities/apple-java-cve-2009-3869/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1643/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1647/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1694/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0408/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2009-3869/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2009-3869/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1560/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1584/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0043/
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=43859, https://www.infosecmatter.com/nessus-plugin-library/?id=49863, https://www.infosecmatter.com/nessus-plugin-library/?id=42926, https://www.infosecmatter.com/nessus-plugin-library/?id=45386, https://www.infosecmatter.com/nessus-plugin-library/?id=42817, https://www.infosecmatter.com/nessus-plugin-library/?id=42851, https://www.infosecmatter.com/nessus-plugin-library/?id=42373, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/multi/browser/java_setdifficm_bof, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/, https://www.infosecmatter.com/list-of-metasploit-linux-exploits-detailed-spreadsheet/
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3, Linux, Mac OS X
2009
Sun Java JRE AWT setDiffICM Buffer Overflow
This module exploits a flaw in the setDiffICM function in the Sun JVM. The payload is serialized and passed to the applet via PARAM tags. It must be a native payload. The effected Java versions are JDK and JRE 6 Update 16 and earlier, JDK and JRE 5.0 Update 21 and earlier, SDK and JRE 1.4.2_23 and earlier, and SDK and JRE 1.3.1_26 and earlier.
Mitigation:
Upgrade to the latest version of Sun Java JRE