CVE-2009-3880
Summary
| CVE | CVE-2009-3880 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-11-09 19:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects that may be sent to loggers, which allows attackers to obtain sensitive information via vectors related to the implementation of Component, KeyboardFocusManager, and DefaultKeyboardFocusManager, aka Bug Id 6664512. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sun | Jre | 1.5.0 | update10 | All | All |
| Application | Sun | Jre | 1.5.0 | update_1 | All | All |
| Application | Sun | Jre | 1.5.0 | update_11 | All | All |
| Application | Sun | Jre | 1.5.0 | update_12 | All | All |
| Application | Sun | Jre | 1.5.0 | update_13 | All | All |
| Application | Sun | Jre | 1.5.0 | update_14 | All | All |
| Application | Sun | Jre | 1.5.0 | update_15 | All | All |
| Application | Sun | Jre | 1.5.0 | update_16 | All | All |
| Application | Sun | Jre | 1.5.0 | update_17 | All | All |
| Application | Sun | Jre | 1.5.0 | update_18 | All | All |
| Application | Sun | Jre | 1.5.0 | update_19 | All | All |
| Application | Sun | Jre | 1.5.0 | update_2 | All | All |
| Application | Sun | Jre | 1.5.0 | update_20 | All | All |
| Application | Sun | Jre | 1.5.0 | update_3 | All | All |
| Application | Sun | Jre | 1.5.0 | update_4 | All | All |
| Application | Sun | Jre | 1.5.0 | update_5 | All | All |
| Application | Sun | Jre | 1.5.0 | update_6 | All | All |
| Application | Sun | Jre | 1.5.0 | update_7 | All | All |
| Application | Sun | Jre | 1.5.0 | update_8 | All | All |
| Application | Sun | Jre | 1.5.0 | update_9 | All | All |
| Application | Sun | Jre | 1.6.0 | update_1 | All | All |
| Application | Sun | Jre | 1.6.0 | update_10 | All | All |
| Application | Sun | Jre | 1.6.0 | update_11 | All | All |
| Application | Sun | Jre | 1.6.0 | update_12 | All | All |
| Application | Sun | Jre | 1.6.0 | update_13 | All | All |
| Application | Sun | Jre | 1.6.0 | update_14 | All | All |
| Application | Sun | Jre | 1.6.0 | update_15 | All | All |
| Application | Sun | Jre | 1.6.0 | update_2 | All | All |
| Application | Sun | Jre | 1.6.0 | update_3 | All | All |
| Application | Sun | Jre | 1.6.0 | update_4 | All | All |
| Application | Sun | Jre | 1.6.0 | update_5 | All | All |
| Application | Sun | Jre | 1.6.0 | update_6 | All | All |
| Application | Sun | Jre | 1.6.0 | update_7 | All | All |
| Application | Sun | Jre | 1.6.0 | update_8 | All | All |
| Application | Sun | Jre | 1.6.0 | update_9 | All | All |
| Application | Sun | Jre | All | update_21 | All | All |
| Application | Sun | Jre | All | update_16 | All | All |
| Application | Sun | Openjdk | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Java SE 6 Update 17 Release Notes. | af854a3a-2127-422b-91ae-364da2661108 | java.sun.com | Vendor Advisory |
| JDK 5.0u22 Release Notes | af854a3a-2127-422b-91ae-364da2661108 | java.sun.com | Vendor Advisory |
| Gentoo Linux Documentation -- Sun JDK/JRE: Multiple vulnerabilites | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Gentoo updates for sun-jre-bin, sun-jdk, blackdown-jre, blackdown-jdk, and emul-linux-x86-java - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Bug 530296 – CVE-2009-3880 OpenJDK UI logging information leakage(6664512) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.