Novell Home

CVE-2009-2676

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2009-2676 at MITRE

Description

Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old version of JNLPAppletLauncher.

NVD CVSS v2 Base Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)

Novell/SUSE information

Novell Bugzilla entry: 528268, 548655

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
openSUSE 10.3
  • java-1_6_0-sun >= 1.6.0.u15-0.1
  • java-1_6_0-sun-alsa >= 1.6.0.u15-0.1
  • java-1_6_0-sun-debuginfo >= 1.6.0.u15-0.1
  • java-1_6_0-sun-demo >= 1.6.0.u15-0.1
  • java-1_6_0-sun-devel >= 1.6.0.u15-0.1
  • java-1_6_0-sun-jdbc >= 1.6.0.u15-0.1
  • java-1_6_0-sun-plugin >= 1.6.0.u15-0.1
  • java-1_6_0-sun-src >= 1.6.0.u15-0.1
openSUSE 10.3
  • java-1_5_0-sun >= 1.5.0_update20-0.1
  • java-1_5_0-sun-alsa >= 1.5.0_update20-0.1
  • java-1_5_0-sun-demo >= 1.5.0_update20-0.1
  • java-1_5_0-sun-devel >= 1.5.0_update20-0.1
  • java-1_5_0-sun-jdbc >= 1.5.0_update20-0.1
  • java-1_5_0-sun-plugin >= 1.5.0_update20-0.1
  • java-1_5_0-sun-src >= 1.5.0_update20-0.1

List of products where fixes are in QA

© 2012 Novell