CVE-2009-2676

Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old version of JNLPAppletLauncher.
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.html
http://marc.info/?l=bugtraq&m=125787273209737&w=2
http://marc.info/?l=bugtraq&m=125787273209737&w=2
http://osvdb.org/56789
http://secunia.com/advisories/36176 Vendor Advisory
http://secunia.com/advisories/36199 Vendor Advisory
http://secunia.com/advisories/36248 Vendor Advisory
http://secunia.com/advisories/37300 Vendor Advisory
http://secunia.com/advisories/37386 Vendor Advisory
http://secunia.com/advisories/37460 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200911-02.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1 Patch
http://sunsolve.sun.com/search/document.do?assetkey=1-66-263490-1 Patch Vendor Advisory
http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html
http://www.securityfocus.com/archive/1/507985/100/0/threaded
http://www.securityfocus.com/bid/35946
http://www.securitytracker.com/id?1022657
http://www.us-cert.gov/cas/techalerts/TA09-294A.html US Government Resource
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
http://www.vupen.com/english/advisories/2009/3316 Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8453
https://rhn.redhat.com/errata/RHSA-2009-1199.html
https://rhn.redhat.com/errata/RHSA-2009-1200.html
http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.html
http://marc.info/?l=bugtraq&m=125787273209737&w=2
http://marc.info/?l=bugtraq&m=125787273209737&w=2
http://osvdb.org/56789
http://secunia.com/advisories/36176 Vendor Advisory
http://secunia.com/advisories/36199 Vendor Advisory
http://secunia.com/advisories/36248 Vendor Advisory
http://secunia.com/advisories/37300 Vendor Advisory
http://secunia.com/advisories/37386 Vendor Advisory
http://secunia.com/advisories/37460 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200911-02.xml
http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1 Patch
http://sunsolve.sun.com/search/document.do?assetkey=1-66-263490-1 Patch Vendor Advisory
http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html
http://www.securityfocus.com/archive/1/507985/100/0/threaded
http://www.securityfocus.com/bid/35946
http://www.securitytracker.com/id?1022657
http://www.us-cert.gov/cas/techalerts/TA09-294A.html US Government Resource
http://www.vmware.com/security/advisories/VMSA-2009-0016.html
http://www.vupen.com/english/advisories/2009/3316 Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8453
https://rhn.redhat.com/errata/RHSA-2009-1199.html
https://rhn.redhat.com/errata/RHSA-2009-1200.html
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:sun:java_se:*:*:*:*:*:*:*:*
cpe:2.3:a:sun:java_se:*:*:business:*:*:*:*:*
OR cpe:2.3:a:sun:jdk:*:update19:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:*:update_14:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update1:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update10:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update11:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update11_b03:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update12:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update13:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update14:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update15:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update16:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update17:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update18:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update2:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update3:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update4:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update5:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update6:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update7:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update8:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.5.0:update9:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_10:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_11:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_12:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_13:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_3:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_4:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_5:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_6:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_7:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update1:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update2:*:*:*:*:*:*
cpe:2.3:a:sun:jre:*:update19:*:*:*:*:*:*
cpe:2.3:a:sun:jre:*:update_14:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update1:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update10:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update11:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update12:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update13:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update14:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update15:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update16:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update17:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update18:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update2:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update3:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update4:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update5:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update6:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update7:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update8:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.5.0:update9:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.6.0:update_1:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.6.0:update_10:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.6.0:update_11:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.6.0:update_12:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.6.0:update_13:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.6.0:update_2:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.6.0:update_3:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.6.0:update_4:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.6.0:update_5:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.6.0:update_6:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.6.0:update_7:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:sun:java_se:*:*:business:*:*:*:*:*
OR cpe:2.3:a:sun:jre:*:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.0_01:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.0_02:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.0_03:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.0_04:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.1:update1:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.1:update2:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.1:update3:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.1:update4:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.1:update5:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.1:update6:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.1:update7:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2:update16:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2:update17:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2:update18:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2:update19:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2:update20:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2_1:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2_2:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2_3:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2_4:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2_5:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2_6:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2_7:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2_8:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2_9:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2_10:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2_11:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2_12:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2_13:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2_14:*:*:*:*:*:*:*
cpe:2.3:a:sun:jre:1.4.2_15:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:*:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.0_01:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.0_02:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.0_03:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.0_04:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.1_01:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.1_02:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.1_03:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.1_04:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.1_05:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.1_06:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.1_07:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_1:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_2:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_3:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_4:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_5:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_6:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_7:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_8:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_9:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_10:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_11:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_12:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_13:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_14:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_15:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_16:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_17:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_18:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_19:*:*:*:*:*:*:*
cpe:2.3:a:sun:sdk:1.4.2_20:*:*:*:*:*:*:*

History

21 Nov 2024, 01:05

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.html - () http://lists.opensuse.org/opensuse-security-announce/2009-08/msg00003.html -
References () http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.html - () http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.html -
References () http://marc.info/?l=bugtraq&m=125787273209737&w=2 - () http://marc.info/?l=bugtraq&m=125787273209737&w=2 -
References () http://osvdb.org/56789 - () http://osvdb.org/56789 -
References () http://secunia.com/advisories/36176 - Vendor Advisory () http://secunia.com/advisories/36176 - Vendor Advisory
References () http://secunia.com/advisories/36199 - Vendor Advisory () http://secunia.com/advisories/36199 - Vendor Advisory
References () http://secunia.com/advisories/36248 - Vendor Advisory () http://secunia.com/advisories/36248 - Vendor Advisory
References () http://secunia.com/advisories/37300 - Vendor Advisory () http://secunia.com/advisories/37300 - Vendor Advisory
References () http://secunia.com/advisories/37386 - Vendor Advisory () http://secunia.com/advisories/37386 - Vendor Advisory
References () http://secunia.com/advisories/37460 - Vendor Advisory () http://secunia.com/advisories/37460 - Vendor Advisory
References () http://security.gentoo.org/glsa/glsa-200911-02.xml - () http://security.gentoo.org/glsa/glsa-200911-02.xml -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1 - Patch () http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1 - Patch
References () http://sunsolve.sun.com/search/document.do?assetkey=1-66-263490-1 - Patch, Vendor Advisory () http://sunsolve.sun.com/search/document.do?assetkey=1-66-263490-1 - Patch, Vendor Advisory
References () http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html - () http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.html -
References () http://www.securityfocus.com/archive/1/507985/100/0/threaded - () http://www.securityfocus.com/archive/1/507985/100/0/threaded -
References () http://www.securityfocus.com/bid/35946 - () http://www.securityfocus.com/bid/35946 -
References () http://www.securitytracker.com/id?1022657 - () http://www.securitytracker.com/id?1022657 -
References () http://www.us-cert.gov/cas/techalerts/TA09-294A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA09-294A.html - US Government Resource
References () http://www.vmware.com/security/advisories/VMSA-2009-0016.html - () http://www.vmware.com/security/advisories/VMSA-2009-0016.html -
References () http://www.vupen.com/english/advisories/2009/3316 - Vendor Advisory () http://www.vupen.com/english/advisories/2009/3316 - Vendor Advisory
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8453 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8453 -
References () https://rhn.redhat.com/errata/RHSA-2009-1199.html - () https://rhn.redhat.com/errata/RHSA-2009-1199.html -
References () https://rhn.redhat.com/errata/RHSA-2009-1200.html - () https://rhn.redhat.com/errata/RHSA-2009-1200.html -

Information

Published : 2009-08-05 19:30

Updated : 2024-11-21 01:05


NVD link : CVE-2009-2676

Mitre link : CVE-2009-2676

CVE.ORG link : CVE-2009-2676


JSON object : View

Products Affected

sun

  • sdk
  • jre
  • jdk
  • java_se