CVE-2009-1106

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.
References
Link Resource
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html
http://marc.info/?l=bugtraq&m=124344236532162&w=2
http://secunia.com/advisories/34496
http://secunia.com/advisories/35156
http://secunia.com/advisories/35255
http://secunia.com/advisories/36185
http://secunia.com/advisories/37386
http://secunia.com/advisories/37460
http://security.gentoo.org/glsa/glsa-200911-02.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1 Patch
http://sunsolve.sun.com/search/document.do?assetkey=1-66-254611-1 Patch Vendor Advisory
http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm
http://www.redhat.com/support/errata/RHSA-2009-0392.html
http://www.redhat.com/support/errata/RHSA-2009-1038.html
http://www.securityfocus.com/archive/1/507985/100/0/threaded
http://www.securityfocus.com/bid/34240
http://www.securitytracker.com/id?1021920
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
http://www.vupen.com/english/advisories/2009/1426
http://www.vupen.com/english/advisories/2009/3316
https://exchange.xforce.ibmcloud.com/vulnerabilities/49459
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6619
https://rhn.redhat.com/errata/RHSA-2009-1198.html
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html
http://marc.info/?l=bugtraq&m=124344236532162&w=2
http://secunia.com/advisories/34496
http://secunia.com/advisories/35156
http://secunia.com/advisories/35255
http://secunia.com/advisories/36185
http://secunia.com/advisories/37386
http://secunia.com/advisories/37460
http://security.gentoo.org/glsa/glsa-200911-02.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1 Patch
http://sunsolve.sun.com/search/document.do?assetkey=1-66-254611-1 Patch Vendor Advisory
http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm
http://www.redhat.com/support/errata/RHSA-2009-0392.html
http://www.redhat.com/support/errata/RHSA-2009-1038.html
http://www.securityfocus.com/archive/1/507985/100/0/threaded
http://www.securityfocus.com/bid/34240
http://www.securitytracker.com/id?1021920
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
http://www.vupen.com/english/advisories/2009/1426
http://www.vupen.com/english/advisories/2009/3316
https://exchange.xforce.ibmcloud.com/vulnerabilities/49459
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6619
https://rhn.redhat.com/errata/RHSA-2009-1198.html
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sun:jdk:1.6.0:update_10:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_11:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_12:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.6.0:update_10:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.6.0:update_11:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.6.0:update_12:*:*:*:*:*:*

History

21 Nov 2024, 01:01

Type Values Removed Values Added
References () http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133 - () http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133 -
References () http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html - () http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html -
References () http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html - () http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html -
References () http://marc.info/?l=bugtraq&m=124344236532162&w=2 - () http://marc.info/?l=bugtraq&m=124344236532162&w=2 -
References () http://secunia.com/advisories/34496 - () http://secunia.com/advisories/34496 -
References () http://secunia.com/advisories/35156 - () http://secunia.com/advisories/35156 -
References () http://secunia.com/advisories/35255 - () http://secunia.com/advisories/35255 -
References () http://secunia.com/advisories/36185 - () http://secunia.com/advisories/36185 -
References () http://secunia.com/advisories/37386 - () http://secunia.com/advisories/37386 -
References () http://secunia.com/advisories/37460 - () http://secunia.com/advisories/37460 -
References () http://security.gentoo.org/glsa/glsa-200911-02.xml - () http://security.gentoo.org/glsa/glsa-200911-02.xml -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1 - Patch () http://sunsolve.sun.com/search/document.do?assetkey=1-21-125137-14-1 - Patch
References () http://sunsolve.sun.com/search/document.do?assetkey=1-66-254611-1 - Patch, Vendor Advisory () http://sunsolve.sun.com/search/document.do?assetkey=1-66-254611-1 - Patch, Vendor Advisory
References () http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm - () http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm -
References () http://www.redhat.com/support/errata/RHSA-2009-0392.html - () http://www.redhat.com/support/errata/RHSA-2009-0392.html -
References () http://www.redhat.com/support/errata/RHSA-2009-1038.html - () http://www.redhat.com/support/errata/RHSA-2009-1038.html -
References () http://www.securityfocus.com/archive/1/507985/100/0/threaded - () http://www.securityfocus.com/archive/1/507985/100/0/threaded -
References () http://www.securityfocus.com/bid/34240 - () http://www.securityfocus.com/bid/34240 -
References () http://www.securitytracker.com/id?1021920 - () http://www.securitytracker.com/id?1021920 -
References () http://www.vmware.com/security/advisories/VMSA-2009-0016.html - () http://www.vmware.com/security/advisories/VMSA-2009-0016.html -
References () http://www.vupen.com/english/advisories/2009/1426 - () http://www.vupen.com/english/advisories/2009/1426 -
References () http://www.vupen.com/english/advisories/2009/3316 - () http://www.vupen.com/english/advisories/2009/3316 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/49459 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/49459 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6619 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6619 -
References () https://rhn.redhat.com/errata/RHSA-2009-1198.html - () https://rhn.redhat.com/errata/RHSA-2009-1198.html -

Information

Published : 2009-03-25 23:30

Updated : 2024-11-21 01:01


NVD link : CVE-2009-1106

Mitre link : CVE-2009-1106

CVE.ORG link : CVE-2009-1106


JSON object : View

Products Affected

sun

  • jre
  • jdk
CWE
CWE-20

Improper Input Validation