CVE-2009-2476
Publication date 10 August 2009
Last updated 24 July 2024
Ubuntu priority
The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object.
Status
Package | Ubuntu Release | Status |
---|---|---|
java | ||
openjdk-6 | ||
sun-java5 | ||
sun-java6 | ||
References
Related Ubuntu Security Notices (USN)
- USN-814-1
- OpenJDK vulnerabilities
- 11 August 2009