CVE-2009-1190

Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
VendorProductVersion
sunjdk
𝑥
≤ 1.5.0
sunjdk
1.1.0
sunjdk
1.1.6
sunjdk
1.1.6
sunjdk
1.1.7b:b
sunjdk
1.1.7b:b
sunjdk
1.1.8
sunjdk
1.1.8
sunjdk
1.1.8
sunjdk
1.1.8
sunjdk
1.1.8
sunjdk
1.1.8
sunjdk
1.2.0
sunjdk
1.2.1
sunjdk
1.2.1
sunjdk
1.2.2
sunjdk
1.2.2
sunjdk
1.3.0
sunjdk
1.3.0_01:_01
sunjdk
1.3.0_02:_02
sunjdk
1.3.0_03:_03
sunjdk
1.3.0_04:_04
sunjdk
1.3.0_05:_05
sunjdk
1.3.1
sunjdk
1.3.1
sunjdk
1.3.1
sunjdk
1.3.1_01:_01
sunjdk
1.3.1_01a:_01a
sunjdk
1.3.1_02:_02
sunjdk
1.3.1_03:_03
sunjdk
1.3.1_04:_04
sunjdk
1.3.1_05:_05
sunjdk
1.3.1_06:_06
sunjdk
1.3.1_07:_07
sunjdk
1.3.1_08:_08
sunjdk
1.3.1_09:_09
sunjdk
1.3.1_10:_10
sunjdk
1.3.1_11:_11
sunjdk
1.3.1_12:_12
sunjdk
1.3.1_13:_13
sunjdk
1.3.1_14:_14
sunjdk
1.3.1_15:_15
sunjdk
1.3.1_16:_16
sunjdk
1.3.1_17:_17
sunjdk
1.3.1_18:_18
sunjdk
1.3.1_19:_19
sunjdk
1.3.1_20:_20
sunjdk
1.3.1_21:_21
sunjdk
1.3.1_22:_22
sunjdk
1.3.1_23:_23
sunjdk
1.3.1_24:_24
sunjdk
1.3.1_25:_25
sunjdk
1.3.1_26:_26
sunjdk
1.3.1_27:_27
sunjdk
1.3.1_28:_28
sunjdk
1.4.0
sunjdk
1.4.0_01:_01
sunjdk
1.4.0_02:_02
sunjdk
1.4.0_03:_03
sunjdk
1.4.0_04:_04
sunjdk
1.4.1
sunjdk
1.4.1_01:_01
sunjdk
1.4.1_02:_02
sunjdk
1.4.1_03:_03
sunjdk
1.4.1_04:_04
sunjdk
1.4.1_05:_05
sunjdk
1.4.1_06:_06
sunjdk
1.4.1_07:_07
sunjdk
1.4.2
sunjdk
1.4.2_1:_1
sunjdk
1.4.2_2:_2
sunjdk
1.4.2_3:_3
sunjdk
1.4.2_4:_4
sunjdk
1.4.2_5:_5
sunjdk
1.4.2_6:_6
sunjdk
1.4.2_7:_7
sunjdk
1.4.2_8:_8
sunjdk
1.4.2_9:_9
sunjdk
1.4.2_10:_10
sunjdk
1.4.2_11:_11
sunjdk
1.4.2_12:_12
sunjdk
1.4.2_13:_13
sunjdk
1.4.2_14:_14
sunjdk
1.4.2_15:_15
sunjdk
1.4.2_16:_16
sunjdk
1.4.2_17:_17
sunjdk
1.4.2_18:_18
sunjdk
1.4.2_19:_19
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0
sunjdk
1.5.0_03:_03
sunjdk
1.5.0_03:_03
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
java
natty
dne
maverick
dne
lucid
dne
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
dapper
dne
openjdk-6
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
dapper
dne
sun-java5
natty
dne
maverick
dne
lucid
dne
karmic
dne
jaunty
ignored
intrepid
ignored
hardy
ignored
dapper
ignored
sun-java6
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
dapper
dne
Common Weakness Enumeration