CVE-2009-3728
09.11.2009, 19:30
Directory traversal vulnerability in the ICC_Profile.getInstance method in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local International Color Consortium (ICC) profile files via a .. (dot dot) in a pathname, aka Bug Id 6631533.
Vendor | Product | Version |
---|---|---|
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.5.0 |
sun | jre | 1.6.0 |
sun | jre | 1.6.0 |
sun | jre | 1.6.0 |
sun | jre | 1.6.0 |
sun | jre | 1.6.0 |
sun | jre | 1.6.0 |
sun | jre | 1.6.0 |
sun | jre | 1.6.0 |
sun | jre | 1.6.0 |
sun | jre | 1.6.0 |
sun | jre | 1.6.0 |
sun | jre | 1.6.0 |
sun | jre | 1.6.0 |
sun | jre | 1.6.0 |
sun | jre | 1.6.0 |
sun | jre | 1.6.0 |
sun | openjdk | * |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
openjdk-6 |
| ||||||||||||||||
sun-java5 |
| ||||||||||||||||
sun-java6 |
|
References