PT-2009-6109 · Sun+2 · Java Se+2

Marc Schoenefeld

·

Published

2009-11-09

·

Updated

2017-09-19

·

CVE-2009-3884

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Sun Java SE versions 5.0 before Update 22 Sun Java SE versions 6 before Update 17 OpenJDK (affected versions not specified)
Description The TimeZone.getTimeZone method allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files.
Recommendations For Sun Java SE versions 5.0 before Update 22, update to Update 22 or later. For Sun Java SE versions 6 before Update 17, update to Update 17 or later. For OpenJDK, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-3884
RHSA-2009:1560
RHSA-2009:1571
RHSA-2009:1584
RHSA-2009:1662
RHSA-2009_1584

Affected Products

Java Se
Openjdk
Red Hat