CVE-2009-3881

Priority
Medium
Description
Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does
not prevent the existence of children of a resurrected ClassLoader, which
allows remote attackers to gain privileges via unspecified vectors, related
to an "information leak vulnerability," aka Bug Id 6636650.
References
Package
Upstream:released (6b17)
Ubuntu 8.04 LTS (Hardy Heron):released (6b18-1.8.2-4ubuntu1~8.04.1)
Ubuntu 10.04 LTS (Lucid Lynx):not-affected (6b17~pre2-0ubuntu3)
Ubuntu 11.04 (Natty Narwhal):not-affected (6b17~pre2-0ubuntu3)
Package
Upstream:released (1.5.0-22)
Ubuntu 8.04 LTS (Hardy Heron):not-affected (1.5.0-22-0ubuntu0.8.04)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 11.04 (Natty Narwhal):DNE
Package
Upstream:released (6.17)
Ubuntu 8.04 LTS (Hardy Heron):released (6.20dlj-0ubuntu1.8.04)
Ubuntu 10.04 LTS (Lucid Lynx):released (6.20dlj-1ubuntu3)
Ubuntu 11.04 (Natty Narwhal):DNE
More Information

Valid XHTML 1.0 Strict

Updated: 2012-06-01 15:20:20 UTC (commit 5347)