Novell Home

CVE-2009-1104

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

CVE-2009-1104 at MITRE

Details

The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; and 1.4.2_19 and earlier does not prevent Javascript that is loaded from the localhost from connecting to other ports on the system, which allows user-assisted attackers to bypass intended access restrictions via LiveConnect, aka CR 6724331. NOTE: this vulnerability can be leveraged with separate cross-site scripting (XSS) vulnerabilities for remote attack vectors.
Novell Bugzilla entries: 488926,497424,516361

SUSE Security Advisories:

Product(s) Fixed package version(s) References
openSUSE 10.3
openSUSE 11.0
  • java-1_5_0-sun >= 1.5.0_update18-0.1
  • java-1_5_0-sun-alsa >= 1.5.0_update18-0.1
  • java-1_5_0-sun-demo >= 1.5.0_update18-0.1
  • java-1_5_0-sun-devel >= 1.5.0_update18-0.1
  • java-1_5_0-sun-jdbc >= 1.5.0_update18-0.1
  • java-1_5_0-sun-plugin >= 1.5.0_update18-0.1
  • java-1_5_0-sun-src >= 1.5.0_update18-0.1
ZYPP Patch Nr: 6125
SAT Patch Nr: 698
openSUSE 11.1
  • java-1_5_0-sun >= 1.5.0_update18-0.1.1
  • java-1_5_0-sun-alsa >= 1.5.0_update18-0.1.1
  • java-1_5_0-sun-devel >= 1.5.0_update18-0.1.1
  • java-1_5_0-sun-jdbc >= 1.5.0_update18-0.1.1
  • java-1_5_0-sun-plugin >= 1.5.0_update18-0.1.1
  • java-1_5_0-sun-src >= 1.5.0_update18-0.1.1
ZYPP Patch Nr: 6125
SAT Patch Nr: 698
Novell Linux POS 9
Open Enterprise Server
SUSE CORE 9 for AMD64 and Intel EM64T
SUSE CORE 9 for IBM POWER
SUSE CORE 9 for IBM S/390 31bit
SUSE CORE 9 for IBM zSeries 64bit
SUSE CORE 9 for x86
  • IBMJava5-JRE >= 1.5.0-0.64
  • IBMJava5-SDK >= 1.5.0-0.64
core9. x86
core9. ppc
core9. x86-64
sles9-oes. x86
core9. s390x
core9. s390
sles9-nlpos. x86
YOU Patch Nr: 12422
SLES 11 DEBUGINFO
  • java-1_6_0-sun-debuginfo >= 1.6.0.u13-0.1.1
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. x86
SAT Patch Nr: 699
SLED 11
  • java-1_6_0-sun >= 1.6.0.u13-0.1.1
  • java-1_6_0-sun-alsa >= 1.6.0.u13-0.1.1
  • java-1_6_0-sun-demo >= 1.6.0.u13-0.1.1
  • java-1_6_0-sun-jdbc >= 1.6.0.u13-0.1.1
  • java-1_6_0-sun-plugin >= 1.6.0.u13-0.1.1
  • java-1_6_0-sun-src >= 1.6.0.u13-0.1.1
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. x86
SAT Patch Nr: 699
SUSE Linux Enterprise Server 10 SP1 for x86
  • java-1_5_0-ibm >= 1.5.0_sr9-2.2.2
  • java-1_5_0-ibm-alsa >= 1.5.0_sr9-2.2.2
  • java-1_5_0-ibm-devel >= 1.5.0_sr9-2.2.2
  • java-1_5_0-ibm-fonts >= 1.5.0_sr9-2.2.2
  • java-1_5_0-ibm-jdbc >= 1.5.0_sr9-2.2.2
  • java-1_5_0-ibm-plugin >= 1.5.0_sr9-2.2.2
sles10-ltss. x86-64
sles10-ltss. x86
sles10-ltss. s390x
ZYPP Patch Nr: 6255
SUSE Linux Enterprise Server 10 SP1 for IBM zSeries 64bit
  • java-1_5_0-ibm >= 1.5.0_sr9-2.2.2
  • java-1_5_0-ibm-32bit >= 1.5.0_sr9-2.2.2
  • java-1_5_0-ibm-devel >= 1.5.0_sr9-2.2.2
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr9-2.2.2
  • java-1_5_0-ibm-fonts >= 1.5.0_sr9-2.2.2
sles10-ltss. x86-64
sles10-ltss. x86
sles10-ltss. s390x
ZYPP Patch Nr: 6255
SUSE Linux Enterprise Server 10 SP1 for AMD64 and Intel EM64T
  • java-1_5_0-ibm >= 1.5.0_sr9-2.2.2
  • java-1_5_0-ibm-32bit >= 1.5.0_sr9-2.2.2
  • java-1_5_0-ibm-alsa-32bit >= 1.5.0_sr9-2.2.2
  • java-1_5_0-ibm-devel >= 1.5.0_sr9-2.2.2
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr9-2.2.2
  • java-1_5_0-ibm-fonts >= 1.5.0_sr9-2.2.2
sles10-ltss. x86-64
sles10-ltss. x86
sles10-ltss. s390x
ZYPP Patch Nr: 6255
SLE 11
  • java-1_6_0-ibm >= 1.6.0-124.7.1
  • java-1_6_0-ibm-devel >= 1.6.0-124.7.1
  • java-1_6_0-ibm-fonts >= 1.6.0-124.7.1
sle11. ppc
sle11. ia64
sle11. s390x
sle11. x86
sle11. x86-64
sle11. s390x
sle11. x86-64
sle11. x86
sle11. ppc
SAT Patch Nr: 1058
SLE 11
  • java-1_6_0-ibm-devel >= 1.6.0-124.7.1
sle11. ppc
sle11. ia64
sle11. s390x
sle11. x86
sle11. x86-64
sle11. s390x
sle11. x86-64
sle11. x86
sle11. ppc
SAT Patch Nr: 1058
SLES 11
  • java-1_6_0-ibm >= 1.6.0-124.7.1
  • java-1_6_0-ibm-alsa >= 1.6.0-124.7.1
  • java-1_6_0-ibm-fonts >= 1.6.0-124.7.1
  • java-1_6_0-ibm-jdbc >= 1.6.0-124.7.1
  • java-1_6_0-ibm-plugin >= 1.6.0-124.7.1
sle11. ppc
sle11. ia64
sle11. s390x
sle11. x86
sle11. x86-64
sle11. s390x
sle11. x86-64
sle11. x86
sle11. ppc
SAT Patch Nr: 1058
SLES 11
  • java-1_6_0-ibm-alsa-x86 >= 1.6.0-124.7.1
  • java-1_6_0-ibm-x86 >= 1.6.0-124.7.1
sle11. ppc
sle11. ia64
sle11. s390x
sle11. x86
sle11. x86-64
sle11. s390x
sle11. x86-64
sle11. x86
sle11. ppc
SAT Patch Nr: 1058
SLES 11
  • java-1_6_0-ibm >= 1.6.0-124.7.1
  • java-1_6_0-ibm-fonts >= 1.6.0-124.7.1
  • java-1_6_0-ibm-jdbc >= 1.6.0-124.7.1
sle11. ppc
sle11. ia64
sle11. s390x
sle11. x86
sle11. x86-64
sle11. s390x
sle11. x86-64
sle11. x86
sle11. ppc
SAT Patch Nr: 1058
openSUSE 10.3
  • java-1_6_0-sun >= 1.6.0.u12-1.4
  • java-1_6_0-sun-alsa >= 1.6.0.u12-1.4
  • java-1_6_0-sun-debuginfo >= 1.6.0.u12-1.4
  • java-1_6_0-sun-demo >= 1.6.0.u12-1.4
  • java-1_6_0-sun-devel >= 1.6.0.u12-1.4
  • java-1_6_0-sun-jdbc >= 1.6.0.u12-1.4
  • java-1_6_0-sun-plugin >= 1.6.0.u12-1.4
  • java-1_6_0-sun-src >= 1.6.0.u12-1.4
ZYPP Patch Nr: 6128
SAT Patch Nr: 705
openSUSE 11.0
  • java-1_6_0-sun >= 1.6.0.u13-0.1
  • java-1_6_0-sun-alsa >= 1.6.0.u13-0.1
  • java-1_6_0-sun-demo >= 1.6.0.u13-0.1
  • java-1_6_0-sun-devel >= 1.6.0.u13-0.1
  • java-1_6_0-sun-jdbc >= 1.6.0.u13-0.1
  • java-1_6_0-sun-plugin >= 1.6.0.u13-0.1
  • java-1_6_0-sun-src >= 1.6.0.u13-0.1
ZYPP Patch Nr: 6128
SAT Patch Nr: 705
openSUSE 11.1
  • java-1_6_0-sun >= 1.6.0.u13-0.1.1
  • java-1_6_0-sun-alsa >= 1.6.0.u13-0.1.1
  • java-1_6_0-sun-devel >= 1.6.0.u13-0.1.1
  • java-1_6_0-sun-jdbc >= 1.6.0.u13-0.1.1
  • java-1_6_0-sun-plugin >= 1.6.0.u13-0.1.1
  • java-1_6_0-sun-src >= 1.6.0.u13-0.1.1
ZYPP Patch Nr: 6128
SAT Patch Nr: 705
SUSE Linux Enterprise Desktop 10 SP2 for x86
  • java-1_5_0-ibm >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-alsa >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-demo >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-devel >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-fonts >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-jdbc >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-plugin >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-src >= 1.5.0_sr9-2.8
sled10-sp2. x86
sles10-sp2. ppc
sled10-sp2. x86-64
sles10-sp2. s390x
sles10-sp2. x86
sles10-sp2. x86-64
ZYPP Patch Nr: 6253
SUSE Linux Enterprise Desktop 10 SP2 for AMD64 and Intel EM64T
  • java-1_5_0-ibm >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-32bit >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-alsa-32bit >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-demo >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-devel >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-fonts >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-src >= 1.5.0_sr9-2.8
sled10-sp2. x86
sles10-sp2. ppc
sled10-sp2. x86-64
sles10-sp2. s390x
sles10-sp2. x86
sles10-sp2. x86-64
ZYPP Patch Nr: 6253
SUSE Linux Enterprise Server 10 SP2 for x86
  • java-1_5_0-ibm >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-alsa >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-devel >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-fonts >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-jdbc >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-plugin >= 1.5.0_sr9-2.8
sled10-sp2. x86
sles10-sp2. ppc
sled10-sp2. x86-64
sles10-sp2. s390x
sles10-sp2. x86
sles10-sp2. x86-64
ZYPP Patch Nr: 6253
SUSE Linux Enterprise Server 10 SP2 for IBM POWER
  • java-1_5_0-ibm >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-64bit >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-devel >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-fonts >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-jdbc >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-plugin >= 1.5.0_sr9-2.8
sled10-sp2. x86
sles10-sp2. ppc
sled10-sp2. x86-64
sles10-sp2. s390x
sles10-sp2. x86
sles10-sp2. x86-64
ZYPP Patch Nr: 6253
SUSE Linux Enterprise Server 10 SP2 for IBM zSeries 64bit
  • java-1_5_0-ibm >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-32bit >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-devel >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-fonts >= 1.5.0_sr9-2.8
sled10-sp2. x86
sles10-sp2. ppc
sled10-sp2. x86-64
sles10-sp2. s390x
sles10-sp2. x86
sles10-sp2. x86-64
ZYPP Patch Nr: 6253
SUSE Linux Enterprise Server 10 SP2 for AMD64 and Intel EM64T
  • java-1_5_0-ibm >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-32bit >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-alsa-32bit >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-devel >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr9-2.8
  • java-1_5_0-ibm-fonts >= 1.5.0_sr9-2.8
sled10-sp2. x86
sles10-sp2. ppc
sled10-sp2. x86-64
sles10-sp2. s390x
sles10-sp2. x86
sles10-sp2. x86-64
ZYPP Patch Nr: 6253

Novell® Making IT Work As One

© 2009 Novell, Inc. All Rights Reserved.