CVE-2009-2674
Publication date 5 August 2009
Last updated 24 July 2024
Ubuntu priority
Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrary code via a crafted JPEG image that is not properly handled during display to a splash screen, which triggers a heap-based buffer overflow.
Status
Package | Ubuntu Release | Status |
---|---|---|
java | ||
openjdk-6 | ||
sun-java5 | ||
sun-java6 | ||
References
Related Ubuntu Security Notices (USN)
- USN-814-1
- OpenJDK vulnerabilities
- 11 August 2009