CVE-2009-2476
10.08.2009, 18:30
The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object.Enginsight
| Vendor | Product | Version |
|---|---|---|
| sun | java_se | 𝑥 ≤ 6 |
| sun | openjdk | * |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| java |
| ||||||||||||||
| openjdk-6 |
| ||||||||||||||
| sun-java5 |
| ||||||||||||||
| sun-java6 |
|
Common Weakness Enumeration
References