Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-3880
HistoryNov 09, 2009 - 12:00 a.m.

CVE-2009-3880

2009-11-0900:00:00
ubuntu.com
ubuntu.com
11

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.005

Percentile

76.9%

The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun
Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not
properly restrict the objects that may be sent to loggers, which allows
attackers to obtain sensitive information via vectors related to the
implementation of Component, KeyboardFocusManager, and
DefaultKeyboardFocusManager, aka Bug Id 6664512.

OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchopenjdk-6< 6b18-1.8.2-4ubuntu1~8.04.1UNKNOWN
ubuntu8.10noarchopenjdk-6< 6b12-0ubuntu6.6UNKNOWN
ubuntu9.04noarchopenjdk-6< 6b14-1.4.1-0ubuntu12UNKNOWN
ubuntu9.10noarchopenjdk-6< 6b16-1.6.1-3ubuntu1UNKNOWN
ubuntu8.04noarchsun-java6< 6.20dlj-0ubuntu1.8.04UNKNOWN
ubuntu9.04noarchsun-java6< 6.20dlj-0ubuntu1.9.04UNKNOWN
ubuntu9.10noarchsun-java6< 6.20dlj-0ubuntu1.9.10UNKNOWN
ubuntu10.04noarchsun-java6< 6.20dlj-1ubuntu3UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.005

Percentile

76.9%