CVE-2009-3864 Information

Description

The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17 when a non-English version of Windows is used does not retrieve available new JRE versions which allows remote attackers to leverage vulnerabilities in older releases of this software aka Bug Id 6869694.

Reference

http://java.sun.com/javase/6/webnotes/6u17.html http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.html http://secunia.com/advisories/37231 http://secunia.com/advisories/37239 http://sunsolve.sun.com/search/document.do?assetkey=1-66-269868-1 http://www.securityfocus.com/bid/36881 http://www.vupen.com/english/advisories/2009/3131 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A6753

Share on: