Oracle Java Runtime Environment 'HsbParser.getSoundBank()' Remote Heap Buffer Overflow Vulnerability
BID:39559
Info
Oracle Java Runtime Environment 'HsbParser.getSoundBank()' Remote Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 39559 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-3910 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 26 2010 12:00AM |
| Updated: | May 18 2010 10:02PM |
| Credit: | Oracle |
| Vulnerable: |
Sun JRE (Windows Production Release) 1.6 _17 Sun JRE (Windows Production Release) 1.6 _13 Sun JRE (Windows Production Release) 1.6 _12 Sun JRE (Windows Production Release) 1.6 _10 Sun JRE (Windows Production Release) 1.6 _07 Sun JRE (Windows Production Release) 1.6 _06 Sun JRE (Windows Production Release) 1.6 _05 Sun JRE (Windows Production Release) 1.6 _04 Sun JRE (Windows Production Release) 1.6 Sun JRE (Windows Production Release) 1.5 _22 Sun JRE (Windows Production Release) 1.5 _18 Sun JRE (Windows Production Release) 1.5 _16 Sun JRE (Windows Production Release) 1.5 _15 Sun JRE (Windows Production Release) 1.5 _06 Sun JRE (Windows Production Release) 1.5 _05 Sun JRE (Windows Production Release) 1.5 _04 Sun JRE (Windows Production Release) 1.5 _03 Sun JRE (Windows Production Release) 1.5 _02 Sun JRE (Windows Production Release) 1.5 _01 Sun JRE (Windows Production Release) 1.5 Sun JRE (Windows Production Release) 1.6.0_2 Sun JRE (Windows Production Release) 1.6.0_18 Sun JRE (Windows Production Release) 1.6.0_15 Sun JRE (Windows Production Release) 1.6.0_14 Sun JRE (Windows Production Release) 1.6.0_11 Sun JRE (Windows Production Release) 1.6.0_03 Sun JRE (Windows Production Release) 1.6.0_02 Sun JRE (Windows Production Release) 1.6.0_01 Sun JRE (Windows Production Release) 1.5.0_23 Sun JRE (Windows Production Release) 1.5.0_20 Sun JRE (Windows Production Release) 1.5.0_17 Sun JRE (Windows Production Release) 1.5.0_14 Sun JRE (Windows Production Release) 1.5.0_13 Sun JRE (Windows Production Release) 1.5.0_12 Sun JRE (Windows Production Release) 1.5.0_11 Sun JRE (Windows Production Release) 1.5.0_10 Sun JRE (Windows Production Release) 1.5.0.0_09 Sun JRE (Windows Production Release) 1.5.0.0_08 Sun JRE (Windows Production Release) 1.5.0.0_07 Sun JRE (Solaris Production Release) 1.6 _17 Sun JRE (Solaris Production Release) 1.6 _13 Sun JRE (Solaris Production Release) 1.6 _12 Sun JRE (Solaris Production Release) 1.6 _10 Sun JRE (Solaris Production Release) 1.6 _07 Sun JRE (Solaris Production Release) 1.6 _06 Sun JRE (Solaris Production Release) 1.6 _05 Sun JRE (Solaris Production Release) 1.6 _04 Sun JRE (Solaris Production Release) 1.6 Sun JRE (Solaris Production Release) 1.5 _22 Sun JRE (Solaris Production Release) 1.5 _18 Sun JRE (Solaris Production Release) 1.5 _16 Sun JRE (Solaris Production Release) 1.5 _15 Sun JRE (Solaris Production Release) 1.5 _06 Sun JRE (Solaris Production Release) 1.5 _05 Sun JRE (Solaris Production Release) 1.5 _04 Sun JRE (Solaris Production Release) 1.5 _03 Sun JRE (Solaris Production Release) 1.5 _02 Sun JRE (Solaris Production Release) 1.5 _01 Sun JRE (Solaris Production Release) 1.5 Sun JRE (Solaris Production Release) 1.6.0_2 Sun JRE (Solaris Production Release) 1.6.0_18 Sun JRE (Solaris Production Release) 1.6.0_15 Sun JRE (Solaris Production Release) 1.6.0_14 Sun JRE (Solaris Production Release) 1.6.0_11 Sun JRE (Solaris Production Release) 1.6.0_03 Sun JRE (Solaris Production Release) 1.6.0_02 Sun JRE (Solaris Production Release) 1.6.0_01 Sun JRE (Solaris Production Release) 1.5.0_23 Sun JRE (Solaris Production Release) 1.5.0_20 Sun JRE (Solaris Production Release) 1.5.0_17 Sun JRE (Solaris Production Release) 1.5.0_14 Sun JRE (Solaris Production Release) 1.5.0_13 Sun JRE (Solaris Production Release) 1.5.0_12 Sun JRE (Solaris Production Release) 1.5.0_11 Sun JRE (Solaris Production Release) 1.5.0_10 Sun JRE (Solaris Production Release) 1.5.0.0_09 Sun JRE (Solaris Production Release) 1.5.0.0_08 Sun JRE (Solaris Production Release) 1.5.0.0_07 Sun JRE (Linux Production Release) 1.6 _17 Sun JRE (Linux Production Release) 1.6 _13 Sun JRE (Linux Production Release) 1.6 _12 Sun JRE (Linux Production Release) 1.6 _10 Sun JRE (Linux Production Release) 1.6 _07 Sun JRE (Linux Production Release) 1.6 _06 Sun JRE (Linux Production Release) 1.6 _05 Sun JRE (Linux Production Release) 1.6 _04 Sun JRE (Linux Production Release) 1.6 Sun JRE (Linux Production Release) 1.5 _22 Sun JRE (Linux Production Release) 1.5 _18 Sun JRE (Linux Production Release) 1.5 _16 Sun JRE (Linux Production Release) 1.5 _15 Sun JRE (Linux Production Release) 1.5 _07 Sun JRE (Linux Production Release) 1.5 _06 Sun JRE (Linux Production Release) 1.5 _05 Sun JRE (Linux Production Release) 1.5 _04 Sun JRE (Linux Production Release) 1.5 _03 Sun JRE (Linux Production Release) 1.5 _02 Sun JRE (Linux Production Release) 1.5 _01 Sun JRE (Linux Production Release) 1.5 .0 beta Sun JRE (Linux Production Release) 1.5 Sun JRE (Linux Production Release) 1.6.0_18 Sun JRE (Linux Production Release) 1.6.0_15 Sun JRE (Linux Production Release) 1.6.0_14 Sun JRE (Linux Production Release) 1.6.0_11 Sun JRE (Linux Production Release) 1.6.0_03 Sun JRE (Linux Production Release) 1.6.0_02 Sun JRE (Linux Production Release) 1.6.0_01 Sun JRE (Linux Production Release) 1.5.0_23 Sun JRE (Linux Production Release) 1.5.0_20 Sun JRE (Linux Production Release) 1.5.0_17 Sun JRE (Linux Production Release) 1.5.0_14 Sun JRE (Linux Production Release) 1.5.0_13 Sun JRE (Linux Production Release) 1.5.0_12 Sun JRE (Linux Production Release) 1.5.0_11 Sun JRE (Linux Production Release) 1.5.0_10 Sun JRE (Linux Production Release) 1.5.0_09 Sun JRE (Linux Production Release) 1.5.0_08 Sun JDK (Windows Production Release) 1.6 _17 Sun JDK (Windows Production Release) 1.6 _14 Sun JDK (Windows Production Release) 1.6 _13 Sun JDK (Windows Production Release) 1.6 _11 Sun JDK (Windows Production Release) 1.6 _10 Sun JDK (Windows Production Release) 1.6 _07 Sun JDK (Windows Production Release) 1.6 _06 Sun JDK (Windows Production Release) 1.6 _05 Sun JDK (Windows Production Release) 1.6 _04 Sun JDK (Windows Production Release) 1.6 Sun JDK (Windows Production Release) 1.5 0_10 Sun JDK (Windows Production Release) 1.5 _22 Sun JDK (Windows Production Release) 1.5 _18 Sun JDK (Windows Production Release) 1.5 _17 Sun JDK (Windows Production Release) 1.5 _15 Sun JDK (Windows Production Release) 1.5 _14 Sun JDK (Windows Production Release) 1.5 _02 Sun JDK (Windows Production Release) 1.5 _01 Sun JDK (Windows Production Release) 1.5 .0_05 Sun JDK (Windows Production Release) 1.5 .0_04 Sun JDK (Windows Production Release) 1.5 .0_03 Sun JDK (Windows Production Release) 1.6.0_18 Sun JDK (Windows Production Release) 1.6.0_15 Sun JDK (Windows Production Release) 1.6.0_03 Sun JDK (Windows Production Release) 1.6.0_02 Sun JDK (Windows Production Release) 1.6.0_01-b06 Sun JDK (Windows Production Release) 1.6.0_01 Sun JDK (Windows Production Release) 1.5.0_23 Sun JDK (Windows Production Release) 1.5.0_20 Sun JDK (Windows Production Release) 1.5.0_16 Sun JDK (Windows Production Release) 1.5.0_13 Sun JDK (Windows Production Release) 1.5.0_12 Sun JDK (Windows Production Release) 1.5.0_11-b03 Sun JDK (Windows Production Release) 1.5.0_07-b03 Sun JDK (Windows Production Release) 1.5.0.0_11 Sun JDK (Windows Production Release) 1.5.0.0_09 Sun JDK (Windows Production Release) 1.5.0.0_08 Sun JDK (Windows Production Release) 1.5.0.0_06 Sun JDK (Solaris Production Release) 1.6 _17 Sun JDK (Solaris Production Release) 1.6 _14 Sun JDK (Solaris Production Release) 1.6 _13 Sun JDK (Solaris Production Release) 1.6 _11 Sun JDK (Solaris Production Release) 1.6 _10 Sun JDK (Solaris Production Release) 1.6 _07 Sun JDK (Solaris Production Release) 1.6 _06 Sun JDK (Solaris Production Release) 1.6 _05 Sun JDK (Solaris Production Release) 1.6 _04 Sun JDK (Solaris Production Release) 1.6 _01-b06 Sun JDK (Solaris Production Release) 1.6 Sun JDK (Solaris Production Release) 1.5 0_10 Sun JDK (Solaris Production Release) 1.5 0_09 Sun JDK (Solaris Production Release) 1.5 0_03 Sun JDK (Solaris Production Release) 1.5 _22 Sun JDK (Solaris Production Release) 1.5 _18 Sun JDK (Solaris Production Release) 1.5 _17 Sun JDK (Solaris Production Release) 1.5 _15 Sun JDK (Solaris Production Release) 1.5 _14 Sun JDK (Solaris Production Release) 1.5 _11-b03 Sun JDK (Solaris Production Release) 1.5 _07-b03 Sun JDK (Solaris Production Release) 1.5 _06 Sun JDK (Solaris Production Release) 1.5 _02 Sun JDK (Solaris Production Release) 1.5 _01 Sun JDK (Solaris Production Release) 1.5 .0_05 Sun JDK (Solaris Production Release) 1.5 .0_04 Sun JDK (Solaris Production Release) 1.5 .0_03 Sun JDK (Solaris Production Release) 1.6.0_18 Sun JDK (Solaris Production Release) 1.6.0_15 Sun JDK (Solaris Production Release) 1.6.0_03 Sun JDK (Solaris Production Release) 1.6.0_02 Sun JDK (Solaris Production Release) 1.6.0_01 Sun JDK (Solaris Production Release) 1.5.0_23 Sun JDK (Solaris Production Release) 1.5.0_20 Sun JDK (Solaris Production Release) 1.5.0_16 Sun JDK (Solaris Production Release) 1.5.0_13 Sun JDK (Solaris Production Release) 1.5.0_12 Sun JDK (Solaris Production Release) 1.5.0_11 Pardus Linux 2009 0 IBM Java SE 5.0 SR11 IBM Java SE 5.0 SR10 Apple Mac OS X Server 10.6.3 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac OS X Server 10.5.8 Apple Mac OS X Server 10.5.7 Apple Mac OS X Server 10.5.6 Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.6 Apple Mac OS X Server 10.5 Apple Mac OS X 10.6.3 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac OS X 10.5.8 Apple Mac OS X 10.5.7 Apple Mac OS X 10.5.6 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.6 Apple Mac OS X 10.5 |
| Not Vulnerable: |
Sun JRE (Windows Production Release) 1.6.0_19 Sun JRE (Solaris Production Release) 1.6.0_19 Sun JDK (Windows Production Release) 1.6.0_19 Sun JDK (Windows Production Release) 1.5.0_24 Sun JDK (Solaris Production Release) 1.6.0_19 Sun JDK (Solaris Production Release) 1.5.0_24 Sun JDK (Linux Production Release) 1.6.0_19 Sun JDK (Linux Production Release) 1.5.0_24 IBM Java SE 5.0 SR11 PF1 |
Discussion
Oracle Java Runtime Environment 'HsbParser.getSoundBank()' Remote Heap Buffer Overflow Vulnerability
Oracle Java SE and Java for Business are prone to a remote heap-based buffer-overflow vulnerability affecting the Java Runtime Environment (JRE).
Attackers can exploit this issue to execute arbitrary code within the context of the user invoking the JRE.
Versions prior to Java 5.0 Update 24 and Java 6.0 Update 19 are vulnerable.
Oracle Java SE and Java for Business are prone to a remote heap-based buffer-overflow vulnerability affecting the Java Runtime Environment (JRE).
Attackers can exploit this issue to execute arbitrary code within the context of the user invoking the JRE.
Versions prior to Java 5.0 Update 24 and Java 6.0 Update 19 are vulnerable.
Exploit / POC
Oracle Java Runtime Environment 'HsbParser.getSoundBank()' Remote Heap Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle Java Runtime Environment 'HsbParser.getSoundBank()' Remote Heap Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references for more information.
Sun JDK (Solaris Production Release) 1.5.0_12
Sun JDK (Solaris Production Release) 1.6.0_18
Sun JDK (Solaris Production Release) 1.5.0_16
Sun JDK (Solaris Production Release) 1.5.0_20
Sun JDK (Solaris Production Release) 1.5 .0_03
Sun JDK (Solaris Production Release) 1.5 _11-b03
Sun JDK (Solaris Production Release) 1.5 .0_04
Sun JDK (Solaris Production Release) 1.5 _06
Sun JDK (Solaris Production Release) 1.5 0_09
Sun JDK (Solaris Production Release) 1.6 _01-b06
Sun JDK (Solaris Production Release) 1.6 _07
Apple Mac OS X 10.6.3
Solution:
Updates are available. Please see the references for more information.
Sun JDK (Solaris Production Release) 1.5.0_12
-
Oracle 118666-26
for SPARC
http://sunsolve.sun.com/pdownload.do?target=118666-26&method=h -
Oracle 118667-26
for SPARC 64bit
http://sunsolve.sun.com/pdownload.do?target=118667-26&method=h -
Oracle 118668-26
for x86
http://sunsolve.sun.com/pdownload.do?target=118668-26&method=h -
Oracle 118669-26
for x86 64bit
http://sunsolve.sun.com/pdownload.do?target=118669-26&method=h
Sun JDK (Solaris Production Release) 1.6.0_18
-
Oracle 125136-21
for SPARC
http://sunsolve.sun.com/pdownload.do?target=125136-21&method=h -
Oracle 125137-21
for SPARC 64bit
http://sunsolve.sun.com/pdownload.do?target=125137-21&method=h -
Oracle 125138-21
for x86
http://sunsolve.sun.com/pdownload.do?target=125138-21&method=h -
Oracle 125139-21
for x86 64bit
http://sunsolve.sun.com/pdownload.do?target=125139-21&method=h
Sun JDK (Solaris Production Release) 1.5.0_16
-
Oracle 118666-26
for SPARC
http://sunsolve.sun.com/pdownload.do?target=118666-26&method=h -
Oracle 118667-26
for SPARC 64bit
http://sunsolve.sun.com/pdownload.do?target=118667-26&method=h -
Oracle 118668-26
for x86
http://sunsolve.sun.com/pdownload.do?target=118668-26&method=h -
Oracle 118669-26
for x86 64bit
http://sunsolve.sun.com/pdownload.do?target=118669-26&method=h
Sun JDK (Solaris Production Release) 1.5.0_20
-
Oracle 118666-26
for SPARC
http://sunsolve.sun.com/pdownload.do?target=118666-26&method=h -
Oracle 118667-26
for SPARC 64bit
http://sunsolve.sun.com/pdownload.do?target=118667-26&method=h -
Oracle 118668-26
for x86
http://sunsolve.sun.com/pdownload.do?target=118668-26&method=h -
Oracle 118669-26
for x86 64bit
http://sunsolve.sun.com/pdownload.do?target=118669-26&method=h
Sun JDK (Solaris Production Release) 1.5 .0_03
-
Oracle 118666-26
for SPARC
http://sunsolve.sun.com/pdownload.do?target=118666-26&method=h -
Oracle 118667-26
for SPARC 64bit
http://sunsolve.sun.com/pdownload.do?target=118667-26&method=h -
Oracle 118668-26
for x86
http://sunsolve.sun.com/pdownload.do?target=118668-26&method=h -
Oracle 118669-26
for x86 64bit
http://sunsolve.sun.com/pdownload.do?target=118669-26&method=h
Sun JDK (Solaris Production Release) 1.5 _11-b03
-
Oracle 118666-26
for SPARC
http://sunsolve.sun.com/pdownload.do?target=118666-26&method=h -
Oracle 118667-26
for SPARC 64bit
http://sunsolve.sun.com/pdownload.do?target=118667-26&method=h -
Oracle 118668-26
for x86
http://sunsolve.sun.com/pdownload.do?target=118668-26&method=h -
Oracle 118669-26
for x86 64bit
http://sunsolve.sun.com/pdownload.do?target=118669-26&method=h
Sun JDK (Solaris Production Release) 1.5 .0_04
-
Oracle 118666-26
for SPARC
http://sunsolve.sun.com/pdownload.do?target=118666-26&method=h -
Oracle 118667-26
for SPARC 64bit
http://sunsolve.sun.com/pdownload.do?target=118667-26&method=h -
Oracle 118668-26
for x86
http://sunsolve.sun.com/pdownload.do?target=118668-26&method=h -
Oracle 118669-26
for x86 64bit
http://sunsolve.sun.com/pdownload.do?target=118669-26&method=h
Sun JDK (Solaris Production Release) 1.5 _06
-
Oracle 118666-26
for SPARC
http://sunsolve.sun.com/pdownload.do?target=118666-26&method=h -
Oracle 118667-26
for SPARC 64bit
http://sunsolve.sun.com/pdownload.do?target=118667-26&method=h -
Oracle 118668-26
for x86
http://sunsolve.sun.com/pdownload.do?target=118668-26&method=h -
Oracle 118669-26
for x86 64bit
http://sunsolve.sun.com/pdownload.do?target=118669-26&method=h
Sun JDK (Solaris Production Release) 1.5 0_09
-
Oracle 118666-26
for SPARC
http://sunsolve.sun.com/pdownload.do?target=118666-26&method=h -
Oracle 118667-26
for SPARC 64bit
http://sunsolve.sun.com/pdownload.do?target=118667-26&method=h -
Oracle 118668-26
for x86
http://sunsolve.sun.com/pdownload.do?target=118668-26&method=h -
Oracle 118669-26
for x86 64bit
http://sunsolve.sun.com/pdownload.do?target=118669-26&method=h
Sun JDK (Solaris Production Release) 1.6 _01-b06
-
Oracle 125136-21
for SPARC
http://sunsolve.sun.com/pdownload.do?target=125136-21&method=h -
Oracle 125137-21
for SPARC 64bit
http://sunsolve.sun.com/pdownload.do?target=125137-21&method=h -
Oracle 125138-21
for x86
http://sunsolve.sun.com/pdownload.do?target=125138-21&method=h -
Oracle 125139-21
for x86 64bit
http://sunsolve.sun.com/pdownload.do?target=125139-21&method=h
Sun JDK (Solaris Production Release) 1.6 _07
-
Oracle 125136-21
for SPARC
http://sunsolve.sun.com/pdownload.do?target=125136-21&method=h -
Oracle 125137-21
for SPARC 64bit
http://sunsolve.sun.com/pdownload.do?target=125137-21&method=h -
Oracle 125138-21
for x86
http://sunsolve.sun.com/pdownload.do?target=125138-21&method=h -
Oracle 125139-21
for x86 64bit
http://sunsolve.sun.com/pdownload.do?target=125139-21&method=h
Apple Mac OS X 10.6.3
-
Apple JavaForMacOSX10.6Update2.dmg
http://www.apple.com/support/downloads/
References
Oracle Java Runtime Environment 'HsbParser.getSoundBank()' Remote Heap Buffer Overflow Vulnerability
References:
References: