Novell Home

CVE-2009-3873

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2009-3873 at MITRE

Description

The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.

NVD CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)

Novell/SUSE information

Novell Bugzilla entries: 552581, 552586, 554069, 561831, 561859, 566705

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 10 SP2 for x86
  • java-1_5_0-ibm >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-alsa >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-demo >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-devel >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-fonts >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-jdbc >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-plugin >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-src >= 1.5.0_sr11-0.4.1
sled10-sp2.x86
sles10-sp2.x86
sles10-sp2.x86-64
sles10-sp2.ppc
sles10-sp2.s390x
sled10-sp2.x86-64
ZYPP Patch Nr: 6740
SUSE Linux Enterprise Desktop 10 SP2 for AMD64 and Intel EM64T
  • java-1_5_0-ibm >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-32bit >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-alsa-32bit >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-demo >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-devel >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-fonts >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-src >= 1.5.0_sr11-0.4.1
sled10-sp2.x86
sles10-sp2.x86
sles10-sp2.x86-64
sles10-sp2.ppc
sles10-sp2.s390x
sled10-sp2.x86-64
ZYPP Patch Nr: 6740
SUSE Linux Enterprise Server 10 SP2 for x86
  • java-1_5_0-ibm >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-alsa >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-devel >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-fonts >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-jdbc >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-plugin >= 1.5.0_sr11-0.4.1
sled10-sp2.x86
sles10-sp2.x86
sles10-sp2.x86-64
sles10-sp2.ppc
sles10-sp2.s390x
sled10-sp2.x86-64
ZYPP Patch Nr: 6740
SUSE Linux Enterprise Server 10 SP2 for IBM POWER
  • java-1_5_0-ibm >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-64bit >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-devel >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-fonts >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-jdbc >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-plugin >= 1.5.0_sr11-0.4.1
sled10-sp2.x86
sles10-sp2.x86
sles10-sp2.x86-64
sles10-sp2.ppc
sles10-sp2.s390x
sled10-sp2.x86-64
ZYPP Patch Nr: 6740
SUSE Linux Enterprise Server 10 SP2 for IBM zSeries 64bit
  • java-1_5_0-ibm >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-32bit >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-devel >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-fonts >= 1.5.0_sr11-0.4.1
sled10-sp2.x86
sles10-sp2.x86
sles10-sp2.x86-64
sles10-sp2.ppc
sles10-sp2.s390x
sled10-sp2.x86-64
ZYPP Patch Nr: 6740
SUSE Linux Enterprise Server 10 SP2 for AMD64 and Intel EM64T
  • java-1_5_0-ibm >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-32bit >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-alsa-32bit >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-devel >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr11-0.4.1
  • java-1_5_0-ibm-fonts >= 1.5.0_sr11-0.4.1
sled10-sp2.x86
sles10-sp2.x86
sles10-sp2.x86-64
sles10-sp2.ppc
sles10-sp2.s390x
sled10-sp2.x86-64
ZYPP Patch Nr: 6740
SUSE Linux Enterprise Server 10 SP2 for x86
  • java-1_4_2-ibm >= 1.4.2_sr13.2-0.4.1
  • java-1_4_2-ibm-devel >= 1.4.2_sr13.2-0.4.1
  • java-1_4_2-ibm-jdbc >= 1.4.2_sr13.2-0.4.1
  • java-1_4_2-ibm-plugin >= 1.4.2_sr13.2-0.4.1
sles10-sp2.ppc
sles10-sp2.s390x
sle10-sp2-sdk.x86
sle10-sp2-sdk.ia64
sle10-sp2-sdk.s390x
sles10-sp2.ia64
sles10-sp2.x86-64
sle10-sp2-sdk.ppc
sle10-sp2-sdk.x86-64
sles10-sp2.x86
ZYPP Patch Nr: 6648
SUSE Linux Enterprise Server 10 SP2 for IBM POWER
  • java-1_4_2-ibm >= 1.4.2_sr13.2-0.4.1
  • java-1_4_2-ibm-devel >= 1.4.2_sr13.2-0.4.1
  • java-1_4_2-ibm-jdbc >= 1.4.2_sr13.2-0.4.1
sles10-sp2.ppc
sles10-sp2.s390x
sle10-sp2-sdk.x86
sle10-sp2-sdk.ia64
sle10-sp2-sdk.s390x
sles10-sp2.ia64
sles10-sp2.x86-64
sle10-sp2-sdk.ppc
sle10-sp2-sdk.x86-64
sles10-sp2.x86
ZYPP Patch Nr: 6648
SUSE Linux Enterprise Server 10 SP2 for AMD64 and Intel EM64T
SUSE Linux Enterprise Server 10 SP2 for IBM zSeries 64bit
SUSE Linux Enterprise Server 10 SP2 for IPF
  • java-1_4_2-ibm >= 1.4.2_sr13.2-0.4.1
  • java-1_4_2-ibm-devel >= 1.4.2_sr13.2-0.4.1
sles10-sp2.ppc
sles10-sp2.s390x
sle10-sp2-sdk.x86
sle10-sp2-sdk.ia64
sle10-sp2-sdk.s390x
sles10-sp2.ia64
sles10-sp2.x86-64
sle10-sp2-sdk.ppc
sle10-sp2-sdk.x86-64
sles10-sp2.x86
ZYPP Patch Nr: 6648
SUSE Linux Enterprise Desktop 10 SP3 for x86
  • java-1_5_0-ibm >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-demo >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-devel >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-fonts >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-jdbc >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-plugin >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-src >= 1.5.0_sr11-0.4.2
sles10-sp3.ppc
sles10-sp3.s390x
sled10-sp3.x86-64
sles10-sp3.x86-64
sled10-sp3.x86
sles10-sp3.x86
ZYPP Patch Nr: 6741
SUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64T
  • java-1_5_0-ibm >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-32bit >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-alsa-32bit >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-demo >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-devel >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-devel-32bit >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-fonts >= 1.5.0_sr11-0.4.2
  • java-1_5_0-ibm-src >= 1.5.0_sr11-0.4.2
sles10-sp3.ppc
sles10-sp3.s390x
sled10-sp3.x86-64
sles10-sp3.x86-64
sled10-sp3.x86
sles10-sp3.x86
ZYPP Patch Nr: 6741
Novell Linux POS 9
Open Enterprise Server
SUSE CORE 9 for AMD64 and Intel EM64T
SUSE CORE 9 for IBM S/390 31bit
SUSE CORE 9 for IBM zSeries 64bit
SUSE CORE 9 for x86
  • IBMJava5-JRE >= 1.5.0-0.76
  • IBMJava5-SDK >= 1.5.0-0.76
core9.s390
core9.x86
sles9-oes.x86
sles9-nlpos.x86
core9.s390x
core9.ppc
core9.x86-64
YOU Patch Nr: 12564
SUSE CORE 9 for IBM POWER
  • IBMJava5-JRE >= 1.5.0-0.78
  • IBMJava5-SDK >= 1.5.0-0.78
core9.s390
core9.x86
sles9-oes.x86
sles9-nlpos.x86
core9.s390x
core9.ppc
core9.x86-64
YOU Patch Nr: 12564

© 2012 Novell