LWN.net Logo

openjdk: arbitrary code execution

Package(s):openjdk-6 CVE #(s):CVE-2009-3885
Created:November 16, 2009 Updated:April 28, 2010
Description:

From the Ubuntu advisory:

Multiple flaws were discovered in JPEG and BMP image handling. If a user were tricked into loading a specially crafted image, a remote attacker could crash the application or run arbitrary code with user privileges. (CVE-2009-3873, CVE-2009-3874, CVE-2009-3885)

Alerts:
Mandriva MDVSA-2010:084 2010-04-28
Ubuntu USN-859-1 2009-11-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds