PT-2009-5983 · Oracle+1 · Java Runtime Environment+2
Marc Schoenefeld
·
Publicado
2009-11-09
·
Atualizado
2018-10-30
·
CVE-2009-3728
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Java Runtime Environment (JRE) versions 5.0 before Update 22
Java Runtime Environment (JRE) versions 6 before Update 17
OpenJDK (affected versions not specified)
Description
A directory traversal issue exists in the ICC Profile.getInstance method, allowing remote attackers to determine the existence of local International Color Consortium (ICC) profile files by using a .. (dot dot) in a pathname.
Recommendations
For Java Runtime Environment (JRE) versions 5.0 before Update 22, update to version 5.0 Update 22 or later.
For Java Runtime Environment (JRE) versions 6 before Update 17, update to version 6 Update 17 or later.
For OpenJDK, at the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Java Runtime Environment
Openjdk
Red Hat