Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Java | — | Upgrade to Apple Java version 1.6.0.17Upgrade to Apple Java version 1.5.0.22Upgrade to Apple Java version 1.4.2.22 | Jan 26, 2012 | Nov 5, 2009 |
| Centos_linux | — | Upgrade java-1.6.0-openjdk-demoUpgrade java-1.6.0-openjdk-develUpgrade java-1.6.0-openjdk-srcUpgrade java-1.6.0-openjdkUpgrade java-1.6.0-openjdk-javadoc | Dec 1, 2016 | Nov 5, 2009 |
| Gentoo Linux | — | Upgrade dev-java/sun-jdk.Upgrade dev-java/blackdown-jdk.Upgrade dev-java/sun-jre-bin.Upgrade dev-java/blackdown-jre.Upgrade app-emulation/emul-linux-x86-java. | Oct 30, 2017 | Nov 5, 2009 |
| Hpux | — | Update Jdk15.JDK15-IPF32 to the latest versionUpdate Jre14.JRE14-IPF32-HS to the latest versionUpdate Jdk14.JDK14-PA20 to the latest versionUpdate Jre14.JRE14-IPF64-HS to the latest versionUpdate Jre15.JRE15-PA20-HS to the latest versionUpdate Jdk60.JDK60-COM to the latest versionUpdate Jre14.JRE14-PA20-HS to the latest versionUpdate Jre60.JRE60-PA20-HS to the latest versionUpdate Jre15.JRE15-PA20W-HS to the latest versionUpdate Jdk14.JDK14-PA11 to the latest versionUpdate Jre60.JRE60-COM to the latest versionUpdate Jre14.JRE14-IPF64 to the latest versionUpdate Jre15.JRE15-IPF32 to the latest versionUpdate Jre60.JRE60-PA20W-HS to the latest versionUpdate Jre15.JRE15-PA20W to the latest versionUpdate Jre14.JRE14-PA20W to the latest versionUpdate Jdk15.JDK15-PA20 to the latest versionUpdate Jre60.JRE60-PA20 to the latest versionUpdate Jdk60.JDK60-IPF32 to the latest versionUpdate Jre14.JRE14-PA11 to the latest versionUpdate Jdk14.JDK14-PA20W to the latest versionUpdate Jre60.JRE60-PA20W to the latest versionUpdate Jre15.JRE15-COM to the latest versionUpdate Jdk60.JDK60-IPF64 to the latest versionUpdate Jre14.JRE14-COM to the latest versionUpdate Jre14.JRE14-PA11-HS to the latest versionUpdate Jre15.JRE15-IPF32-HS to the latest versionUpdate Jre15.JRE15-IPF64-HS to the latest versionUpdate Jdk14.JDK14-IPF32 to the latest versionUpdate Jdk14.JDK14-IPF64 to the latest versionUpdate Jre14.JRE14-PA20W-HS to the latest versionUpdate Jre60.JRE60-IPF32-HS to the latest versionUpdate Jre60.JRE60-IPF32 to the latest versionUpdate Jre60.JRE60-IPF64-HS to the latest versionUpdate Jre15.JRE15-IPF64 to the latest versionUpdate Jre15.JRE15-PA20 to the latest versionUpdate Jdk14.JDK14-COM to the latest versionUpdate Jdk15.JDK15-PA20W to the latest versionUpdate Jdk15.JDK15-IPF64 to the latest versionUpdate Jdk60.JDK60-PA20W to the latest versionUpdate Jre14.JRE14-IPF32 to the latest versionUpdate Jdk60.JDK60-PA20 to the latest versionUpdate Jre60.JRE60-IPF64 to the latest versionUpdate Jdk15.JDK15-COM to the latest versionUpdate Jre14.JRE14-PA20 to the latest version | Aug 11, 2017 | Nov 5, 2009 |
| Oracle_linux | — | Upgrade java-1.6.0-openjdk-srcUpgrade java-1.6.0-openjdk-develUpgrade java-1.6.0-openjdk-javadocUpgrade java-1.6.0-openjdkUpgrade java-1.6.0-openjdk-demo | Oct 16, 2024 | Nov 5, 2009 |
| Suse | — | Upgrade java-1_6_0-ibm-x86Upgrade java-1_6_0-ibmUpgrade java-1_6_0-ibm-jdbcUpgrade java-1_6_0-ibm-alsaUpgrade java-1_6_0-ibm-alsa-x86Upgrade java-1_6_0-ibm-pluginUpgrade java-1_6_0-ibm-fonts | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade icedtea6-pluginUpgrade openjdk-6-jre | Nov 8, 2024 | Nov 5, 2009 |
| Vmsa 2010 0002 3 Java Jre Security Update | — | Upgrade VMware ESX 3.5 to build number 227413Upgrade VMware ESX 4.0 to build number 256968 | Sep 2, 2010 | Nov 5, 2009 |
| Vmsa 2010 0005 | — | Apply ESX350-201003403-SG. | Feb 16, 2011 | Nov 5, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub