Oracle Java运行时环境JPEG图形解析堆溢出漏洞

admin 2022-07-23 14:57:52 CNNVD漏洞 来源:ZONE.CI 全球网 0 阅读模式

漏洞信息详情

Oracle Java运行时环境JPEG图形解析堆溢出漏洞

  • CNNVD编号:CNNVD-200910-324
  • 危害等级: 超危
  • CVE编号: CVE-2009-3403
  • 漏洞类型: 资料不足
  • 发布时间: 2009-08-03
  • 威胁类型: 远程
  • 更新时间: 2009-10-22
  • 厂        商: oracle
  • 漏洞来源: ZDIhttp://www.zero...

漏洞简介

Solaris系统的Java运行时环境(JRE)为JAVA应用程序提供可靠的运行环境。 JRE中负责为Web Start应用加载JPEG启动屏幕的代码中存在整数溢出漏洞。在处理启动屏幕的某些部分时,javaws.exe错误的计算后所使用的内存分配,在之后的解压中Java Web Start会将数据写入错误分配的缓冲区中,最终会触发堆溢出,导致以当前用户权限执行任意代码。

漏洞公告

目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接: S.u.S.E. openSUSE 10.3 S.u.S.E. java-1_5_0-sun-1.5.0_update20-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_5_0-sun-1.5.0 _update20-0.1.i586.rpm S.u.S.E. java-1_5_0-sun-1.5.0_update20-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_5_0-sun-1.5 .0_update20-0.1.x86_64.rpm S.u.S.E. java-1_5_0-sun-alsa-1.5.0_update20-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_5_0-sun-alsa- 1.5.0_update20-0.1.i586.rpm S.u.S.E. java-1_5_0-sun-alsa-1.5.0_update20-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_5_0-sun-als a-1.5.0_update20-0.1.x86_64.rpm S.u.S.E. java-1_5_0-sun-demo-1.5.0_update20-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_5_0-sun-demo- 1.5.0_update20-0.1.i586.rpm S.u.S.E. java-1_5_0-sun-demo-1.5.0_update20-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_5_0-sun-dem o-1.5.0_update20-0.1.x86_64.rpm S.u.S.E. java-1_5_0-sun-devel-1.5.0_update20-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_5_0-sun-devel -1.5.0_update20-0.1.i586.rpm S.u.S.E. java-1_5_0-sun-devel-1.5.0_update20-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_5_0-sun-dev el-1.5.0_update20-0.1.x86_64.rpm S.u.S.E. java-1_5_0-sun-jdbc-1.5.0_update20-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_5_0-sun-jdbc- 1.5.0_update20-0.1.i586.rpm S.u.S.E. java-1_5_0-sun-jdbc-1.5.0_update20-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_5_0-sun-jdb c-1.5.0_update20-0.1.x86_64.rpm S.u.S.E. java-1_5_0-sun-plugin-1.5.0_update20-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_5_0-sun-plugi n-1.5.0_update20-0.1.i586.rpm S.u.S.E. java-1_5_0-sun-src-1.5.0_update20-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_5_0-sun-src-1 .5.0_update20-0.1.i586.rpm S.u.S.E. java-1_5_0-sun-src-1.5.0_update20-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_5_0-sun-src -1.5.0_update20-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_6_0-sun-1.6.0 .u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_6_0-sun-1.6 .0.u15-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-alsa-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_6_0-sun-alsa- 1.6.0.u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-alsa-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_6_0-sun-als a-1.6.0.u15-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-debuginfo-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/10.3/rpm/i586/java-1_6_0-sun-debug info-1.6.0.u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-debuginfo-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/10.3/rpm/x86_64/java-1_6_0-sun-deb uginfo-1.6.0.u15-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-demo-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_6_0-sun-demo- 1.6.0.u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-demo-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_6_0-sun-dem o-1.6.0.u15-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-devel-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_6_0-sun-devel -1.6.0.u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-devel-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_6_0-sun-dev el-1.6.0.u15-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-jdbc-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_6_0-sun-jdbc- 1.6.0.u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-jdbc-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_6_0-sun-jdb c-1.6.0.u15-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-plugin-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_6_0-sun-plugi n-1.6.0.u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-plugin-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_6_0-sun-plu gin-1.6.0.u15-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-src-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_6_0-sun-src-1 .6.0.u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-src-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_6_0-sun-src -1.6.0.u15-0.1.x86_64.rpm Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu icedtea6-plugin_6b12-0ubuntu6.5_powerpc.deb http://ports.ubuntu.com/pool/main/o/openjdk-6/icedtea6-plugin_6b12-0ub untu6.5_powerpc.deb Ubuntu openjdk-6-dbg_6b12-0ubuntu6.5_powerpc.deb http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-dbg_6b12-0ubun tu6.5_powerpc.deb Ubuntu openjdk-6-demo_6b12-0ubuntu6.5_powerpc.deb http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-demo_6b12-0ubu ntu6.5_powerpc.deb Ubuntu openjdk-6-doc_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-doc_ 6b12-0ubuntu6.5_all.deb Ubuntu openjdk-6-jdk_6b12-0ubuntu6.5_powerpc.deb http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-jdk_6b12-0ubun tu6.5_powerpc.deb Ubuntu openjdk-6-jre-headless_6b12-0ubuntu6.5_powerpc.deb http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-jre-headless_6 b12-0ubuntu6.5_powerpc.deb Ubuntu openjdk-6-jre-lib_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jre- lib_6b12-0ubuntu6.5_all.deb Ubuntu openjdk-6-jre_6b12-0ubuntu6.5_powerpc.deb http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-jre_6b12-0ubun tu6.5_powerpc.deb Ubuntu openjdk-6-source-files_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/universe/o/openjdk-6/openjdk-6- source-files_6b12-0ubuntu6.5_all.deb Ubuntu openjdk-6-source_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-sour ce_6b12-0ubuntu6.5_all.deb Ubuntu Ubuntu Linux 8.10 i386 Ubuntu icedtea6-plugin_6b12-0ubuntu6.5_i386.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/icedtea6-plugi n_6b12-0ubuntu6.5_i386.deb Ubuntu openjdk-6-dbg_6b12-0ubuntu6.5_i386.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-dbg_ 6b12-0ubuntu6.5_i386.deb Ubuntu openjdk-6-demo_6b12-0ubuntu6.5_i386.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-demo _6b12-0ubuntu6.5_i386.deb Ubuntu openjdk-6-doc_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-doc_ 6b12-0ubuntu6.5_all.deb Ubuntu openjdk-6-jdk_6b12-0ubuntu6.5_i386.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jdk_ 6b12-0ubuntu6.5_i386.deb Ubuntu openjdk-6-jre-headless_6b12-0ubuntu6.5_i386.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jre- headless_6b12-0ubuntu6.5_i386.deb Ubuntu openjdk-6-jre-lib_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jre- lib_6b12-0ubuntu6.5_all.deb Ubuntu openjdk-6-jre_6b12-0ubuntu6.5_i386.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jre_ 6b12-0ubuntu6.5_i386.deb Ubuntu openjdk-6-source-files_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/universe/o/openjdk-6/openjdk-6- source-files_6b12-0ubuntu6.5_all.deb Ubuntu openjdk-6-source_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-sour ce_6b12-0ubuntu6.5_all.deb S.u.S.E. openSUSE 11.1 S.u.S.E. java-1_5_0-sun-1.5.0_update20-0.1.1.i586.rpm http://download.opensuse.org/update/11.1/rpm/i586/java-1_5_0-sun-1.5.0 _update20-0.1.1.i586.rpm S.u.S.E. java-1_5_0-sun-1.5.0_update20-0.1.1.x86_64.rpm http://download.opensuse.org/update/11.1/rpm/x86_64/java-1_5_0-sun-1.5 .0_update20-0.1.1.x86_64.rpm S.u.S.E. java-1_5_0-sun-alsa-1.5.0_update20-0.1.1.i586.rpm http://download.opensuse.org/update/11.1/rpm/i586/java-1_5_0-sun-alsa- 1.5.0_update20-0.1.1.i586.rpm S.u.S.E. java-1_5_0-sun-alsa-1.5.0_update20-0.1.1.x86_64.rpm http://download.opensuse.org/update/11.1/rpm/x86_64/java-1_5_0-sun-als a-1.5.0_update20-0.1.1.x86_64.rpm S

参考网址

来源: US-CERT 名称: TA09-294A 链接:http://www.us-cert.gov/cas/techalerts/TA09-294A.HTML 来源: www.oracle.com 链接:http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.HTML 来源: SECTRACK 名称: 1023058 链接:http://www.securitytracker.com/id?1023058 来源: BID 名称: 36746 链接:http://www.securityfocus.com/bid/36746 来源: SECUNIA 名称: 37099 链接:http://secunia.com/advisories/37099 来源: OSVDB 名称: 59118 链接:http://osvdb.org/59118

受影响实体

  • Oracle Bea_product_suite:R27.6.4  

补丁

    暂无

weinxin
特别声明
本站(ZONE.CI)所有文章仅供技术研究,若将其信息做其他用途,由用户承担全部法律及连带责任,本站不承担任何法律及连带责任,请遵守中华人民共和国安全法.
评论:0   参与:  0