The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://java.sun.com/j2se/1.5.0/ReleaseNotes.html - Vendor Advisory | |
References | () http://java.sun.com/javase/6/webnotes/6u17.html - Vendor Advisory | |
References | () http://lists.apple.com/archives/security-announce/2009/Dec/msg00000.html - | |
References | () http://lists.apple.com/archives/security-announce/2009/Dec/msg00001.html - | |
References | () http://secunia.com/advisories/37386 - | |
References | () http://secunia.com/advisories/37581 - | |
References | () http://security.gentoo.org/glsa/glsa-200911-02.xml - | |
References | () http://support.apple.com/kb/HT3969 - | |
References | () http://support.apple.com/kb/HT3970 - | |
References | () http://www.mandriva.com/security/advisories?name=MDVSA-2010:084 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=530300 - Vendor Advisory | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11686 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6960 - |
Information
Published : 2009-11-09 19:30
Updated : 2024-11-21 01:08
NVD link : CVE-2009-3884
Mitre link : CVE-2009-3884
CVE.ORG link : CVE-2009-3884
JSON object : View
Products Affected
sun
- openjdk
- jre
CWE