Vulnerability Name:

CVE-2009-2205 (CCN-53586)

Assigned:2009-09-03
Published:2009-09-03
Updated:2009-09-19
Summary:Stack-based buffer overflow in the Java Web Start command launcher in Java for Mac OS X 10.5 before Update 5 allows attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2009-2205

Source: APPLE
Type: Patch, Vendor Advisory
APPLE-SA-2009-09-03-1

Source: CCN
Type: Apple Mailing List, Thu, 3 Sep 2009 10:14:56 -0700
APPLE-SA-2009-09-03-1 Java for Mac OS X 10.5 Update 5

Source: CCN
Type: SECTRACK ID: 1022820
Java Web Start Stack Overflow in Command Launcher Lets Remote Users Execute Arbitrary Code

Source: SECTRACK
Type: Patch
1022820

Source: CCN
Type: OSVDB ID: 57912
Java on Apple Mac OS X Java Web Start Command Launcher Unspecified Overflow

Source: VUPEN
Type: UNKNOWN
ADV-2009-2543

Source: XF
Type: UNKNOWN
java-jws-macosx-bo(53586)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:apple:mac_os_x:10.5:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.0:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.2:2008-002:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.3:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.4:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.5:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.6:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.7:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.0:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.3:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.4:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.5:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.6:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.7:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:apple:java:1.4:2:*:*:*:*:*:*
  • OR cpe:/a:apple:java:1.4:2_16:*:*:*:*:*:*
  • OR cpe:/a:apple:java:1.4:2_18:*:*:*:*:*:*
  • OR cpe:/a:apple:java:1.4:21:*:*:*:*:*:* (Version <= 2)
  • OR cpe:/a:apple:java:1.5:19:*:*:*:*:*:* (Version <= 0)
  • OR cpe:/a:apple:java:1.6:0:*:*:*:*:*:*
  • OR cpe:/a:apple:java:1.6:0_05:*:*:*:*:*:*
  • OR cpe:/a:apple:java:1.6:0_07:*:*:*:*:*:*
  • OR cpe:/a:apple:java:1.6:13:*:*:*:*:*:* (Version <= 0)

  • Configuration CCN 1:
  • cpe:/o:apple:mac_os_x:10.5:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.3:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.3:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.4:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.4:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.5:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.5:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.6:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.6:*:*:*:*:*:*:*
  • OR cpe:/a:apple:java:1.4:2:*:*:*:*:*:*
  • OR cpe:/a:apple:java:1.4:2_16:*:*:*:*:*:*
  • OR cpe:/a:apple:java:1.4:2_18:*:*:*:*:*:*
  • OR cpe:/a:apple:java:1.6:0:*:*:*:*:*:*
  • OR cpe:/a:apple:java:1.6:0_05:*:*:*:*:*:*
  • OR cpe:/a:apple:java:1.6:0_07:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.0:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.0:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.7:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x_server:10.5.7:*:*:*:*:*:*:*
  • OR cpe:/o:apple:mac_os_x:10.5.2:2008-002:*:*:*:*:*:*
  • OR cpe:/a:apple:java:1.4:2_21:*:*:*:*:*:*
  • OR cpe:/a:apple:java:1.5:0_19:*:*:*:*:*:*
  • OR cpe:/a:apple:java:1.6:0_13:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    apple mac os x 10.5
    apple mac os x 10.5.0
    apple mac os x 10.5.1
    apple mac os x 10.5.2
    apple mac os x 10.5.2 2008-002
    apple mac os x 10.5.3
    apple mac os x 10.5.4
    apple mac os x 10.5.5
    apple mac os x 10.5.6
    apple mac os x 10.5.7
    apple mac os x server 10.5
    apple mac os x server 10.5.0
    apple mac os x server 10.5.1
    apple mac os x server 10.5.2
    apple mac os x server 10.5.3
    apple mac os x server 10.5.4
    apple mac os x server 10.5.5
    apple mac os x server 10.5.6
    apple mac os x server 10.5.7
    apple java 1.4 2
    apple java 1.4 2 16
    apple java 1.4 2 18
    apple java 1.4 * 21
    apple java 1.5 * 19
    apple java 1.6 0
    apple java 1.6 0 05
    apple java 1.6 0 07
    apple java 1.6 * 13
    apple mac os x 10.5
    apple mac os x server 10.5
    apple mac os x 10.5.1
    apple mac os x server 10.5.1
    apple mac os x 10.5.2
    apple mac os x server 10.5.2
    apple mac os x server 10.5.3
    apple mac os x 10.5.3
    apple mac os x 10.5.4
    apple mac os x server 10.5.4
    apple mac os x 10.5.5
    apple mac os x server 10.5.5
    apple mac os x 10.5.6
    apple mac os x server 10.5.6
    apple java 1.4 2
    apple java 1.4 2_16
    apple java 1.4 2_18
    apple java 1.6 0
    apple java 1.6 0_05
    apple java 1.6 0_07
    apple mac os x 10.5.0
    apple mac os x server 10.5.0
    apple mac os x 10.5.7
    apple mac os x server 10.5.7
    apple mac os x 10.5.2 2008-002
    apple java 1.4 2_21
    apple java 1.5 0_19
    apple java 1.6 0_13