CVE-2009-1101

EUVD-2009-1102
Unspecified vulnerability in the lightweight HTTP server implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to cause a denial of service (probably resource consumption) for a JAX-WS service endpoint via a connection without any data, which triggers a file descriptor "leak."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
sunjdk
𝑥
≤ 1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjdk
1.6.0
sunjre
𝑥
≤ 1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
sunjre
1.6.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openjdk-6
dapper
dne
gutsy
dne
hardy
Fixed 6b18-1.8.2-4ubuntu1~8.04.1
released
intrepid
Fixed 6b12-0ubuntu6.4
released
jaunty
not-affected
karmic
not-affected
lucid
not-affected
maverick
not-affected
sun-java5
dapper
ignored
gutsy
ignored
hardy
not-affected
intrepid
ignored
jaunty
not-affected
karmic
dne
lucid
dne
maverick
dne
sun-java6
dapper
dne
gutsy
ignored
hardy
Fixed 6.20dlj-0ubuntu1.8.04
released
intrepid
ignored
jaunty
Fixed 6.20dlj-0ubuntu1.9.04
released
karmic
Fixed 6.20dlj-0ubuntu1.9.10
released
lucid
Fixed 6.20dlj-1ubuntu3
released
maverick
not-affected
References