cvelist/2009/2xxx/CVE-2009-2475.json
2017-10-16 12:31:07 -04:00

121 lines
4.0 KiB
JSON

{
"CVE_data_meta" : {
"ASSIGNER" : "cve@mitre.org",
"ID" : "CVE-2009-2475",
"STATE" : "PUBLIC"
},
"affects" : {
"vendor" : {
"vendor_data" : [
{
"product" : {
"product_data" : [
{
"product_name" : "n/a",
"version" : {
"version_data" : [
{
"version_value" : "n/a"
}
]
}
}
]
},
"vendor_name" : "n/a"
}
]
}
},
"data_format" : "MITRE",
"data_type" : "CVE",
"data_version" : "4.0",
"description" : {
"description_data" : [
{
"lang" : "eng",
"value" : "Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables that are declared without the final keyword, related to (1) LayoutQueue, (2) Cursor.predefined, (3) AccessibleResourceBundle.getContents, (4) ImageReaderSpi.STANDARD_INPUT_TYPE, (5) ImageWriterSpi.STANDARD_OUTPUT_TYPE, (6) the imageio plugins, (7) DnsContext.debug, (8) RmfFileReader/StandardMidiFileWriter.types, (9) AbstractSaslImpl.logger, (10) Synth.Region.uiToRegionMap/lowerCaseNameMap, (11) the Introspector class and a cache of BeanInfo, and (12) JAX-WS, a different vulnerability than CVE-2009-2673."
}
]
},
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng",
"value" : "n/a"
}
]
}
]
},
"references" : {
"reference_data" : [
{
"url" : "http://java.sun.com/j2se/1.5.0/ReleaseNotes.html"
},
{
"url" : "http://java.sun.com/javase/6/webnotes/6u15.html"
},
{
"url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-21-118667-22-1"
},
{
"url" : "http://sunsolve.sun.com/search/document.do?assetkey=1-21-125139-16-1"
},
{
"url" : "https://bugzilla.redhat.com/show_bug.cgi?id=513215"
},
{
"url" : "http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.html"
},
{
"url" : "https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.html"
},
{
"url" : "https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.html"
},
{
"url" : "http://security.gentoo.org/glsa/glsa-200911-02.xml"
},
{
"url" : "http://www.mandriva.com/security/advisories?name=MDVSA-2009:209"
},
{
"url" : "https://rhn.redhat.com/errata/RHSA-2009-1199.html"
},
{
"url" : "https://rhn.redhat.com/errata/RHSA-2009-1200.html"
},
{
"url" : "https://rhn.redhat.com/errata/RHSA-2009-1201.html"
},
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html"
},
{
"url" : "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10221"
},
{
"url" : "http://secunia.com/advisories/36162"
},
{
"url" : "http://secunia.com/advisories/36176"
},
{
"url" : "http://secunia.com/advisories/36180"
},
{
"url" : "http://secunia.com/advisories/36199"
},
{
"url" : "http://secunia.com/advisories/37386"
},
{
"url" : "http://www.vupen.com/english/advisories/2009/2543"
}
]
}
}