Novell Home

CVE-2009-3867

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2009-3867 at MITRE

Description

Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.

NVD CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)

Novell/SUSE information

Novell Bugzilla entries: 552581, 552586, 561831, 561859, 566705

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
Open Enterprise Server
  • IBMJava2-JRE >= 1.4.2_sr13.3-0.7
  • IBMJava2-SDK >= 1.4.2_sr13.3-0.7
core9.x86-64
sles9-oes.x86
core9.ia64
core9.s390x
core9.x86
core9.ppc
core9.s390
sles9-nlpos.x86
YOU Patch Nr: 12565
SUSE Linux Enterprise Server for SAP 10 SP2
  • java-1_5_0-ibm >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-32bit >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-alsa-32bit >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-devel >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-fonts >= 1.5.0_sr11-0.4.1
sled10-sp2.x86
sles10-sp2.x86
sles10-sp2.x86-64
sles10-sp2.ppc
sles10-sp2.s390x
sled10-sp2.x86-64
ZYPP Patch Nr: 6740
SUSE Linux Enterprise SDK 11 GA
  • java-1_4_2-ibm >= 1.4.2_sr13.3-1.1.1
  • java-1_4_2-ibm-devel >= 1.4.2_sr13.3-1.1.1
sle11-sdk.x86-64
sle11-sdk.x86
sle11-sdk.ppc
sles11.ia64
sle11-sdk.ia64
sle11-sdk.s390x
sles11.x86-64
sles11.s390x
sles11.x86
sles11.ppc
SAT Patch Nr: 1744
SUSE Linux Enterprise SDK 11 GA
  • java-1_4_2-ibm-devel >= 1.4.2_sr13.3-1.1.1
sle11-sdk.x86-64
sle11-sdk.x86
sle11-sdk.ppc
sles11.ia64
sle11-sdk.ia64
sle11-sdk.s390x
sles11.x86-64
sles11.s390x
sles11.x86
sles11.ppc
SAT Patch Nr: 1744
SUSE Linux Enterprise Server 11 GA
  • java-1_4_2-ibm >= 1.4.2_sr13.3-1.1.1
  • java-1_4_2-ibm-jdbc >= 1.4.2_sr13.3-1.1.1
  • java-1_4_2-ibm-plugin >= 1.4.2_sr13.3-1.1.1
sle11-sdk.x86-64
sle11-sdk.x86
sle11-sdk.ppc
sles11.ia64
sle11-sdk.ia64
sle11-sdk.s390x
sles11.x86-64
sles11.s390x
sles11.x86
sles11.ppc
SAT Patch Nr: 1744
SUSE Linux Enterprise Server 11 GA
  • java-1_4_2-ibm >= 1.4.2_sr13.3-1.1.1
sle11-sdk.x86-64
sle11-sdk.x86
sle11-sdk.ppc
sles11.ia64
sle11-sdk.ia64
sle11-sdk.s390x
sles11.x86-64
sles11.s390x
sles11.x86
sles11.ppc
SAT Patch Nr: 1744
SUSE Linux Enterprise SDK 11 GA
  • java-1_6_0-ibm >= 1.6.0_sr7.0-1.1.1
  • java-1_6_0-ibm-devel >= 1.6.0_sr7.0-1.1.1
  • java-1_6_0-ibm-fonts >= 1.6.0_sr7.0-1.1.1
sle11-sdk.x86-64
sles11.x86
sle11-sdk.ppc
sles11.x86-64
sle11-sdk.x86
sles11.ppc
sles11.s390x
sle11-sdk.s390x
SAT Patch Nr: 1748
SUSE Linux Enterprise SDK 11 GA
  • java-1_6_0-ibm-devel >= 1.6.0_sr7.0-1.1.1
sle11-sdk.x86-64
sles11.x86
sle11-sdk.ppc
sles11.x86-64
sle11-sdk.x86
sles11.ppc
sles11.s390x
sle11-sdk.s390x
SAT Patch Nr: 1748
SUSE Linux Enterprise Server 11 GA
  • java-1_6_0-ibm >= 1.6.0_sr7.0-1.1.1
  • java-1_6_0-ibm-alsa >= 1.6.0_sr7.0-1.1.1
  • java-1_6_0-ibm-fonts >= 1.6.0_sr7.0-1.1.1
  • java-1_6_0-ibm-jdbc >= 1.6.0_sr7.0-1.1.1
  • java-1_6_0-ibm-plugin >= 1.6.0_sr7.0-1.1.1
sle11-sdk.x86-64
sles11.x86
sle11-sdk.ppc
sles11.x86-64
sle11-sdk.x86
sles11.ppc
sles11.s390x
sle11-sdk.s390x
SAT Patch Nr: 1748
SUSE Linux Enterprise Server 11 GA
  • java-1_6_0-ibm >= 1.6.0_sr7.0-1.1.1
  • java-1_6_0-ibm-fonts >= 1.6.0_sr7.0-1.1.1
  • java-1_6_0-ibm-jdbc >= 1.6.0_sr7.0-1.1.1
sle11-sdk.x86-64
sles11.x86
sle11-sdk.ppc
sles11.x86-64
sle11-sdk.x86
sles11.ppc
sles11.s390x
sle11-sdk.s390x
SAT Patch Nr: 1748
openSUSE 11.0
  • java-1_5_0-sun >= 1.5.0_update22-0.1
  • java-1_5_0-sun-alsa >= 1.5.0_update22-0.1
  • java-1_5_0-sun-demo >= 1.5.0_update22-0.1
  • java-1_5_0-sun-devel >= 1.5.0_update22-0.1
  • java-1_5_0-sun-jdbc >= 1.5.0_update22-0.1
  • java-1_5_0-sun-plugin >= 1.5.0_update22-0.1
  • java-1_5_0-sun-src >= 1.5.0_update22-0.1
openSUSE 11.1
  • java-1_5_0-sun >= 1.5.0_update22-0.1.1
  • java-1_5_0-sun-alsa >= 1.5.0_update22-0.1.1
  • java-1_5_0-sun-devel >= 1.5.0_update22-0.1.1
  • java-1_5_0-sun-jdbc >= 1.5.0_update22-0.1.1
  • java-1_5_0-sun-plugin >= 1.5.0_update22-0.1.1
  • java-1_5_0-sun-src >= 1.5.0_update22-0.1.1
SUSE Linux Enterprise 11 Moblin 2.0
  • java-1_6_0-sun-debuginfo >= 1.6.0.u17-1.1.1
SAT Patch Nr: 1543
SUSE Linux Enterprise 11 Moblin 2.0
  • java-1_6_0-sun >= 1.6.0.u17-1.1.1
  • java-1_6_0-sun-plugin >= 1.6.0.u17-1.1.1
SAT Patch Nr: 1543
SUSE Linux Enterprise Desktop 10 SP3 for x86
  • java-1_5_0-ibm >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-demo >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-devel >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-fonts >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-jdbc >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-plugin >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-src >= 1.5.0_sr11-0.4.2
sles10-sp3.ppc
sles10-sp3.s390x
sled10-sp3.x86-64
sles10-sp3.x86-64
sled10-sp3.x86
sles10-sp3.x86
ZYPP Patch Nr: 6741
SUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64T
  • java-1_5_0-ibm >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-32bit >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-alsa-32bit >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-demo >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-devel >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-fonts >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-src >= 1.5.0_sr11-0.4.2
sles10-sp3.ppc
sles10-sp3.s390x
sled10-sp3.x86-64
sles10-sp3.x86-64
sled10-sp3.x86
sles10-sp3.x86
ZYPP Patch Nr: 6741
SUSE Linux Enterprise Server 10 SP3
  • java-1_5_0-ibm >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-devel >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-fonts >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-jdbc >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-plugin >= 1.5.0_sr11-0.4.2
sles10-sp3.ppc
sles10-sp3.s390x
sled10-sp3.x86-64
sles10-sp3.x86-64
sled10-sp3.x86
sles10-sp3.x86
ZYPP Patch Nr: 6741
SUSE Linux Enterprise Server 10 SP3
  • java-1_5_0-ibm >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-64bit >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-devel >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-fonts >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-jdbc >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-plugin >= 1.5.0_sr11-0.4.2
sles10-sp3.ppc
sles10-sp3.s390x
sled10-sp3.x86-64
sles10-sp3.x86-64
sled10-sp3.x86
sles10-sp3.x86
ZYPP Patch Nr: 6741
SUSE Linux Enterprise Server 10 SP3
  • java-1_5_0-ibm >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-32bit >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-devel >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-fonts >= 1.5.0_sr11-0.4.2
sles10-sp3.ppc
sles10-sp3.s390x
sled10-sp3.x86-64
sles10-sp3.x86-64
sled10-sp3.x86
sles10-sp3.x86
ZYPP Patch Nr: 6741
SUSE Linux Enterprise SDK 10 SP3
  • java-1_5_0-ibm >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-32bit >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-alsa-32bit >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-devel >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-fonts >= 1.5.0_sr11-0.4.2
sles10-sp3.ppc
sles10-sp3.s390x
sled10-sp3.x86-64
sles10-sp3.x86-64
sled10-sp3.x86
sles10-sp3.x86
ZYPP Patch Nr: 6741
Open Enterprise Server
  • IBMJava5-JRE >= 1.5.0-0.76
  • IBMJava5-SDK >= 1.5.0-0.76
core9.s390
core9.x86
sles9-oes.x86
sles9-nlpos.x86
core9.s390x
core9.ppc
core9.x86-64
YOU Patch Nr: 12564
openSUSE 11.0
  • java-1_6_0-sun >= 1.6.0.u17-1.1
  • java-1_6_0-sun-alsa >= 1.6.0.u17-1.1
  • java-1_6_0-sun-demo >= 1.6.0.u17-1.1
  • java-1_6_0-sun-devel >= 1.6.0.u17-1.1
  • java-1_6_0-sun-jdbc >= 1.6.0.u17-1.1
  • java-1_6_0-sun-plugin >= 1.6.0.u17-1.1
  • java-1_6_0-sun-src >= 1.6.0.u17-1.1
openSUSE 11.1
openSUSE 11.2
  • java-1_6_0-sun >= 1.6.0.u17-1.1.1
  • java-1_6_0-sun-alsa >= 1.6.0.u17-1.1.1
  • java-1_6_0-sun-devel >= 1.6.0.u17-1.1.1
  • java-1_6_0-sun-jdbc >= 1.6.0.u17-1.1.1
  • java-1_6_0-sun-plugin >= 1.6.0.u17-1.1.1
  • java-1_6_0-sun-src >= 1.6.0.u17-1.1.1
SUSE Linux Enterprise 11 GA DEBUGINFO
  • java-1_6_0-sun-debuginfo >= 1.6.0.u17-1.1.1
sled11.x86-64
sled11.x86
sle11-debuginfo.x86
sle11-debuginfo.x86-64
SAT Patch Nr: 1542
SUSE Linux Enterprise Desktop 11 GA
  • java-1_6_0-sun >= 1.6.0.u17-1.1.1
  • java-1_6_0-sun-alsa >= 1.6.0.u17-1.1.1
  • java-1_6_0-sun-demo >= 1.6.0.u17-1.1.1
  • java-1_6_0-sun-jdbc >= 1.6.0.u17-1.1.1
  • java-1_6_0-sun-plugin >= 1.6.0.u17-1.1.1
  • java-1_6_0-sun-src >= 1.6.0.u17-1.1.1
sled11.x86-64
sled11.x86
sle11-debuginfo.x86
sle11-debuginfo.x86-64
SAT Patch Nr: 1542
SUSE Linux Enterprise SDK 10 SP2
  • java-1_4_2-ibm >= 1.4.2_sr13.3-1.4.1
  • java-1_4_2-ibm-devel >= 1.4.2_sr13.3-1.4.1
  • java-1_4_2-ibm-jdbc >= 1.4.2_sr13.3-1.4.1
  • java-1_4_2-ibm-plugin >= 1.4.2_sr13.3-1.4.1
sles10-sp2.x86
sle10-sp2-sdk.x86-64
sles10-sp2.s390x
sles10-sp2.ppc
sles10-sp2.ia64
sles10-sp2.x86-64
sle10-sp2-sdk.ppc
sle10-sp2-sdk.ia64
sle10-sp2-sdk.x86
sle10-sp2-sdk.s390x
ZYPP Patch Nr: 6757
SUSE Linux Enterprise SDK 10 SP2
SUSE Linux Enterprise Server for SAP 10 SP2
  • java-1_4_2-ibm >= 1.4.2_sr13.3-1.4.1
  • java-1_4_2-ibm-devel >= 1.4.2_sr13.3-1.4.1
sles10-sp2.x86
sle10-sp2-sdk.x86-64
sles10-sp2.s390x
sles10-sp2.ppc
sles10-sp2.ia64
sles10-sp2.x86-64
sle10-sp2-sdk.ppc
sle10-sp2-sdk.ia64
sle10-sp2-sdk.x86
sle10-sp2-sdk.s390x
ZYPP Patch Nr: 6757
SUSE Linux Enterprise SDK 10 SP2
  • java-1_4_2-ibm >= 1.4.2_sr13.3-1.4.1
  • java-1_4_2-ibm-devel >= 1.4.2_sr13.3-1.4.1
  • java-1_4_2-ibm-jdbc >= 1.4.2_sr13.3-1.4.1
sles10-sp2.x86
sle10-sp2-sdk.x86-64
sles10-sp2.s390x
sles10-sp2.ppc
sles10-sp2.ia64
sles10-sp2.x86-64
sle10-sp2-sdk.ppc
sle10-sp2-sdk.ia64
sle10-sp2-sdk.x86
sle10-sp2-sdk.s390x
ZYPP Patch Nr: 6757
SUSE Linux Enterprise SDK 10 SP3
SUSE Linux Enterprise Server 10 SP3
  • java-1_4_2-ibm >= 1.4.2_sr13.3-1.4.1
  • java-1_4_2-ibm-devel >= 1.4.2_sr13.3-1.4.1
  • java-1_4_2-ibm-jdbc >= 1.4.2_sr13.3-1.4.1
sle10-sp3-sdk.ia64
sles10-sp3.x86-64
sle10-sp3-sdk.ppc
sle10-sp3-sdk.s390x
sles10-sp3.ppc
sles10-sp3.s390x
sle10-sp3-sdk.x86
sles10-sp3.x86
sle10-sp3-sdk.x86-64
sles10-sp3.ia64
ZYPP Patch Nr: 6755
SUSE Linux Enterprise SDK 10 SP3
SUSE Linux Enterprise Server 10 SP3
  • java-1_4_2-ibm >= 1.4.2_sr13.3-1.4.1
  • java-1_4_2-ibm-devel >= 1.4.2_sr13.3-1.4.1
sle10-sp3-sdk.ia64
sles10-sp3.x86-64
sle10-sp3-sdk.ppc
sle10-sp3-sdk.s390x
sles10-sp3.ppc
sles10-sp3.s390x
sle10-sp3-sdk.x86
sles10-sp3.x86
sle10-sp3-sdk.x86-64
sles10-sp3.ia64
ZYPP Patch Nr: 6755

© 2014 Novell