PT-2009-5983 · Oracle+1 · Java Runtime Environment+2

Marc Schoenefeld

·

Published

2009-11-09

·

Updated

2018-10-30

·

CVE-2009-3728

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Java Runtime Environment (JRE) versions 5.0 before Update 22 Java Runtime Environment (JRE) versions 6 before Update 17 OpenJDK (affected versions not specified)
Description A directory traversal issue exists in the ICC Profile.getInstance method, allowing remote attackers to determine the existence of local International Color Consortium (ICC) profile files by using a .. (dot dot) in a pathname.
Recommendations For Java Runtime Environment (JRE) versions 5.0 before Update 22, update to version 5.0 Update 22 or later. For Java Runtime Environment (JRE) versions 6 before Update 17, update to version 6 Update 17 or later. For OpenJDK, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-3728
RHSA-2009:1560
RHSA-2009:1571
RHSA-2009:1584
RHSA-2009:1662
RHSA-2009_1584

Affected Products

Java Runtime Environment
Openjdk
Red Hat