CVE-2009-1099
Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via crafted glyph descriptions in a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via crafted glyph descriptions in a Type1 font, which bypasses a signed comparison and triggers a buffer overflow.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 5.66% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- sun/java runtime environment · sun/java se development kit
- Source
- cve@mitre.org
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01745133
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=777
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2009-07/msg00001.html
- http://marc.info/?l=bugtraq&m=124344236532162&w=2
- http://secunia.com/advisories/34495Vendor Advisory
- http://secunia.com/advisories/34496Vendor Advisory
- http://secunia.com/advisories/35156Vendor Advisory
- http://secunia.com/advisories/35223Vendor Advisory
- http://secunia.com/advisories/35255Vendor Advisory
- http://secunia.com/advisories/35416Vendor Advisory
- http://secunia.com/advisories/35776Vendor Advisory
- http://secunia.com/advisories/36185Vendor Advisory
- http://secunia.com/advisories/37386Vendor Advisory
- http://secunia.com/advisories/37460Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200911-02.xml
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-118669-19-1Patch, Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-254571-1Patch, Vendor Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2009-108.htm
- http://support.avaya.com/elmodocs2/security/ASA-2009-109.htm
- http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html
- http://www.redhat.com/support/errata/RHSA-2009-0392.html
- http://www.redhat.com/support/errata/RHSA-2009-0394.html
- http://www.redhat.com/support/errata/RHSA-2009-1038.html
- http://www.securityfocus.com/archive/1/507985/100/0/threaded
- http://www.securityfocus.com/bid/34240
- http://www.securitytracker.com/id?1021913
- http://www.vmware.com/security/advisories/VMSA-2009-0016.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.