漏洞信息详情
Oracle Java运行时环境JPEG图形解析堆溢出漏洞
- CNNVD编号:CNNVD-200910-324
- 危害等级: 超危
- CVE编号: CVE-2009-3403
- 漏洞类型: 资料不足
- 发布时间: 2009-08-03
- 威胁类型: 远程
- 更新时间: 2009-10-22
- 厂 商: oracle
- 漏洞来源: ZDIhttp://www.zero...
漏洞简介
Solaris系统的Java运行时环境(JRE)为JAVA应用程序提供可靠的运行环境。 JRE中负责为Web Start应用加载JPEG启动屏幕的代码中存在整数溢出漏洞。在处理启动屏幕的某些部分时,javaws.exe错误的计算后所使用的内存分配,在之后的解压中Java Web Start会将数据写入错误分配的缓冲区中,最终会触发堆溢出,导致以当前用户权限执行任意代码。
漏洞公告
目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接: S.u.S.E. openSUSE 10.3 S.u.S.E. java-1_5_0-sun-1.5.0_update20-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_5_0-sun-1.5.0 _update20-0.1.i586.rpm S.u.S.E. java-1_5_0-sun-1.5.0_update20-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_5_0-sun-1.5 .0_update20-0.1.x86_64.rpm S.u.S.E. java-1_5_0-sun-alsa-1.5.0_update20-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_5_0-sun-alsa- 1.5.0_update20-0.1.i586.rpm S.u.S.E. java-1_5_0-sun-alsa-1.5.0_update20-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_5_0-sun-als a-1.5.0_update20-0.1.x86_64.rpm S.u.S.E. java-1_5_0-sun-demo-1.5.0_update20-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_5_0-sun-demo- 1.5.0_update20-0.1.i586.rpm S.u.S.E. java-1_5_0-sun-demo-1.5.0_update20-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_5_0-sun-dem o-1.5.0_update20-0.1.x86_64.rpm S.u.S.E. java-1_5_0-sun-devel-1.5.0_update20-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_5_0-sun-devel -1.5.0_update20-0.1.i586.rpm S.u.S.E. java-1_5_0-sun-devel-1.5.0_update20-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_5_0-sun-dev el-1.5.0_update20-0.1.x86_64.rpm S.u.S.E. java-1_5_0-sun-jdbc-1.5.0_update20-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_5_0-sun-jdbc- 1.5.0_update20-0.1.i586.rpm S.u.S.E. java-1_5_0-sun-jdbc-1.5.0_update20-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_5_0-sun-jdb c-1.5.0_update20-0.1.x86_64.rpm S.u.S.E. java-1_5_0-sun-plugin-1.5.0_update20-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_5_0-sun-plugi n-1.5.0_update20-0.1.i586.rpm S.u.S.E. java-1_5_0-sun-src-1.5.0_update20-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_5_0-sun-src-1 .5.0_update20-0.1.i586.rpm S.u.S.E. java-1_5_0-sun-src-1.5.0_update20-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_5_0-sun-src -1.5.0_update20-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_6_0-sun-1.6.0 .u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_6_0-sun-1.6 .0.u15-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-alsa-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_6_0-sun-alsa- 1.6.0.u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-alsa-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_6_0-sun-als a-1.6.0.u15-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-debuginfo-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/10.3/rpm/i586/java-1_6_0-sun-debug info-1.6.0.u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-debuginfo-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/10.3/rpm/x86_64/java-1_6_0-sun-deb uginfo-1.6.0.u15-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-demo-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_6_0-sun-demo- 1.6.0.u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-demo-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_6_0-sun-dem o-1.6.0.u15-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-devel-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_6_0-sun-devel -1.6.0.u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-devel-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_6_0-sun-dev el-1.6.0.u15-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-jdbc-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_6_0-sun-jdbc- 1.6.0.u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-jdbc-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_6_0-sun-jdb c-1.6.0.u15-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-plugin-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_6_0-sun-plugi n-1.6.0.u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-plugin-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_6_0-sun-plu gin-1.6.0.u15-0.1.x86_64.rpm S.u.S.E. java-1_6_0-sun-src-1.6.0.u15-0.1.i586.rpm http://download.opensuse.org/update/11.0/rpm/i586/java-1_6_0-sun-src-1 .6.0.u15-0.1.i586.rpm S.u.S.E. java-1_6_0-sun-src-1.6.0.u15-0.1.x86_64.rpm http://download.opensuse.org/update/11.0/rpm/x86_64/java-1_6_0-sun-src -1.6.0.u15-0.1.x86_64.rpm Ubuntu Ubuntu Linux 8.10 powerpc Ubuntu icedtea6-plugin_6b12-0ubuntu6.5_powerpc.deb http://ports.ubuntu.com/pool/main/o/openjdk-6/icedtea6-plugin_6b12-0ub untu6.5_powerpc.deb Ubuntu openjdk-6-dbg_6b12-0ubuntu6.5_powerpc.deb http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-dbg_6b12-0ubun tu6.5_powerpc.deb Ubuntu openjdk-6-demo_6b12-0ubuntu6.5_powerpc.deb http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-demo_6b12-0ubu ntu6.5_powerpc.deb Ubuntu openjdk-6-doc_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-doc_ 6b12-0ubuntu6.5_all.deb Ubuntu openjdk-6-jdk_6b12-0ubuntu6.5_powerpc.deb http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-jdk_6b12-0ubun tu6.5_powerpc.deb Ubuntu openjdk-6-jre-headless_6b12-0ubuntu6.5_powerpc.deb http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-jre-headless_6 b12-0ubuntu6.5_powerpc.deb Ubuntu openjdk-6-jre-lib_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jre- lib_6b12-0ubuntu6.5_all.deb Ubuntu openjdk-6-jre_6b12-0ubuntu6.5_powerpc.deb http://ports.ubuntu.com/pool/main/o/openjdk-6/openjdk-6-jre_6b12-0ubun tu6.5_powerpc.deb Ubuntu openjdk-6-source-files_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/universe/o/openjdk-6/openjdk-6- source-files_6b12-0ubuntu6.5_all.deb Ubuntu openjdk-6-source_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-sour ce_6b12-0ubuntu6.5_all.deb Ubuntu Ubuntu Linux 8.10 i386 Ubuntu icedtea6-plugin_6b12-0ubuntu6.5_i386.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/icedtea6-plugi n_6b12-0ubuntu6.5_i386.deb Ubuntu openjdk-6-dbg_6b12-0ubuntu6.5_i386.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-dbg_ 6b12-0ubuntu6.5_i386.deb Ubuntu openjdk-6-demo_6b12-0ubuntu6.5_i386.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-demo _6b12-0ubuntu6.5_i386.deb Ubuntu openjdk-6-doc_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-doc_ 6b12-0ubuntu6.5_all.deb Ubuntu openjdk-6-jdk_6b12-0ubuntu6.5_i386.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jdk_ 6b12-0ubuntu6.5_i386.deb Ubuntu openjdk-6-jre-headless_6b12-0ubuntu6.5_i386.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jre- headless_6b12-0ubuntu6.5_i386.deb Ubuntu openjdk-6-jre-lib_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jre- lib_6b12-0ubuntu6.5_all.deb Ubuntu openjdk-6-jre_6b12-0ubuntu6.5_i386.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-jre_ 6b12-0ubuntu6.5_i386.deb Ubuntu openjdk-6-source-files_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/universe/o/openjdk-6/openjdk-6- source-files_6b12-0ubuntu6.5_all.deb Ubuntu openjdk-6-source_6b12-0ubuntu6.5_all.deb http://security.ubuntu.com/ubuntu/pool/main/o/openjdk-6/openjdk-6-sour ce_6b12-0ubuntu6.5_all.deb S.u.S.E. openSUSE 11.1 S.u.S.E. java-1_5_0-sun-1.5.0_update20-0.1.1.i586.rpm http://download.opensuse.org/update/11.1/rpm/i586/java-1_5_0-sun-1.5.0 _update20-0.1.1.i586.rpm S.u.S.E. java-1_5_0-sun-1.5.0_update20-0.1.1.x86_64.rpm http://download.opensuse.org/update/11.1/rpm/x86_64/java-1_5_0-sun-1.5 .0_update20-0.1.1.x86_64.rpm S.u.S.E. java-1_5_0-sun-alsa-1.5.0_update20-0.1.1.i586.rpm http://download.opensuse.org/update/11.1/rpm/i586/java-1_5_0-sun-alsa- 1.5.0_update20-0.1.1.i586.rpm S.u.S.E. java-1_5_0-sun-alsa-1.5.0_update20-0.1.1.x86_64.rpm http://download.opensuse.org/update/11.1/rpm/x86_64/java-1_5_0-sun-als a-1.5.0_update20-0.1.1.x86_64.rpm S
参考网址
来源: US-CERT 名称: TA09-294A 链接:http://www.us-cert.gov/cas/techalerts/TA09-294A.HTML 来源: www.oracle.com 链接:http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuoct2009.HTML 来源: SECTRACK 名称: 1023058 链接:http://www.securitytracker.com/id?1023058 来源: BID 名称: 36746 链接:http://www.securityfocus.com/bid/36746 来源: SECUNIA 名称: 37099 链接:http://secunia.com/advisories/37099 来源: OSVDB 名称: 59118 链接:http://osvdb.org/59118
受影响实体
- Oracle Bea_product_suite:R27.6.4
补丁
暂无
![weinxin](http://zone.ci/zone_ci_images/zone.ci.png)
评论