CVE-2009-3867
Vulnerability Summary
Timeline
Description
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.
CVSS Metrics
- v2.0•HIGH•Score: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 89.24%• Percentile: 100%
Techniques & Countermeasures
- CWE-119•Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
Affected Systems
- sun•jdk
1.5.0:update_1 | 1.5.0:update_10 | 1.5.0:update_11 | 1.5.0:update_12 | 1.5.0:update_13 | 1.5.0:update_14 | 1.5.0:update_15 | 1.5.0:update_16 | 1.5.0:update_17 | 1.5.0:update_18 | 1.5.0:update_19 | 1.5.0:update_2 | 1.5.0:update_20 | 1.5.0:update_21 | 1.5.0:update_3 | 1.5.0:update_4 | 1.5.0:update_5 | 1.5.0:update_6 | 1.5.0:update_7 | 1.5.0:update_8 | 1.5.0:update_9 | 1.6.0:update_1 | 1.6.0:update_10 | 1.6.0:update_11 | 1.6.0:update_12 | 1.6.0:update_13 | 1.6.0:update_14 | 1.6.0:update_15 | 1.6.0:update_16 | 1.6.0:update_3 | 1.6.0:update_4 | 1.6.0:update_5 | 1.6.0:update_6 | 1.6.0:update_7 | 1.6.0:update_8 | 1.6.0:update_9 | 1.6.0:update2
- sun•jre
1.5.0:update_1 | 1.5.0:update_11 | 1.5.0:update_12 | 1.5.0:update_13 | 1.5.0:update_14 | 1.5.0:update_15 | 1.5.0:update_16 | 1.5.0:update_17 | 1.5.0:update_18 | 1.5.0:update_19 | 1.5.0:update_2 | 1.5.0:update_20 | 1.5.0:update_21 | 1.5.0:update_3 | 1.5.0:update_4 | 1.5.0:update_5 | 1.5.0:update_6 | 1.5.0:update_7 | 1.5.0:update_8 | 1.5.0:update_9 | 1.6.0:update_1 | 1.6.0:update_10 | 1.6.0:update_11 | 1.6.0:update_12 | 1.6.0:update_13 | 1.6.0:update_14 | 1.6.0:update_15 | 1.6.0:update_16 | 1.6.0:update_2 | 1.6.0:update_3 | 1.6.0:update_4 | 1.6.0:update_5 | 1.6.0:update_6 | 1.6.0:update_7 | 1.6.0:update_8 | 1.6.0:update_9 | 1.4.2_1 | 1.4.2_2 | 1.4.2_02 | 1.4.2_03 | 1.4.2_3 | 1.4.2_4 | 1.4.2_04 | 1.4.2_05 | 1.4.2_5 | 1.4.2_06 | 1.4.2_6 | 1.4.2_7 | 1.4.2_07 | 1.4.2_8 | 1.4.2_08 | 1.4.2_09 | 1.4.2_9 | 1.4.2_10 | 1.4.2_11 | 1.4.2_12 | 1.4.2_13 | 1.4.2_14 | 1.4.2_15 | 1.4.2_16 | 1.4.2_17 | 1.4.2_18 | 1.4.2_19 | 1.4.2_20 | 1.4.2_21 | 1.4.2_22 | 1.3.1_1 | 1.3.1_01 | 1.3.1_01a | 1.3.1_02 | 1.3.1_2 | 1.3.1_03 | 1.3.1_3 | 1.3.1_4 | 1.3.1_04 | 1.3.1_05 | 1.3.1_5 | 1.3.1_06 | 1.3.1_6 | 1.3.1_07 | 1.3.1_7 | 1.3.1_8 | 1.3.1_08 | 1.3.1_9 | 1.3.1_09 | 1.3.1_10 | 1.3.1_11 | 1.3.1_12 | 1.3.1_13 | 1.3.1_14 | 1.3.1_15 | 1.3.1_16 | 1.3.1_17 | 1.3.1_18 | 1.3.1_19 | 1.3.1_20 | 1.3.1_21 | 1.3.1_22 | 1.3.1_23 | 1.3.1_24 | 1.3.1_25 | 1.4.2_01
- sun•sdk
1.4.2_01 | 1.4.2_1 | 1.4.2_2 | 1.4.2_02 | 1.4.2_03 | 1.4.2_3 | 1.4.2_04 | 1.4.2_4 | 1.4.2_5 | 1.4.2_05 | 1.4.2_6 | 1.4.2_06 | 1.4.2_07 | 1.4.2_7 | 1.4.2_8 | 1.4.2_08 | 1.4.2_09 | 1.4.2_9 | 1.4.2_10 | 1.4.2_11 | 1.4.2_12 | 1.4.2_13 | 1.4.2_14 | 1.4.2_15 | 1.4.2_16 | 1.4.2_17 | 1.4.2_18 | 1.4.2_19 | 1.4.2_20 | 1.4.2_21 | 1.4.2_22 | 1.3.1_01 | 1.3.1_01a | 1.3.1_2 | 1.3.1_02 | 1.3.1_03 | 1.3.1_3 | 1.3.1_4 | 1.3.1_04 | 1.3.1_5 | 1.3.1_05 | 1.3.1_6 | 1.3.1_06 | 1.3.1_7 | 1.3.1_07 | 1.3.1_8 | 1.3.1_08 | 1.3.1_9 | 1.3.1_09 | 1.3.1_10 | 1.3.1_11 | 1.3.1_12 | 1.3.1_13 | 1.3.1_14 | 1.3.1_15 | 1.3.1_16 | 1.3.1_17 | 1.3.1_18 | 1.3.1_19 | 1.3.1_20 | 1.3.1_21 | 1.3.1_22 | 1.3.1_23 | 1.3.1_24 | 1.3.1_25
References (25)
- http://zerodayinitiative.com/advisories/ZDI-09-076/
- http://marc.info/?l=bugtraq&m=126566824131534&w=2
- http://www.securityfocus.com/bid/36881
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6746
- http://support.apple.com/kb/HT3970
- http://marc.info/?l=bugtraq&m=134254866602253&w=2
- http://support.apple.com/kb/HT3969
- http://marc.info/?l=bugtraq&m=131593453929393&w=2
- http://security.gentoo.org/glsa/glsa-200911-02.xml
- http://www.redhat.com/support/errata/RHSA-2009-1694.html
- http://lists.apple.com/archives/security-announce/2009/Dec/msg00000.html
- http://secunia.com/advisories/37231
- http://securitytracker.com/id?1023132
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.html
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1
- http://www.vupen.com/english/advisories/2009/3131
- http://lists.apple.com/archives/security-announce/2009/Dec/msg00001.html
- http://secunia.com/advisories/37581
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11903
- http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.html
- http://java.sun.com/javase/6/webnotes/6u17.html
- http://secunia.com/advisories/37841
- http://secunia.com/advisories/37239
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7750
- http://secunia.com/advisories/37386