Candidate: CVE-2009-1104 PublicDate: 2009-03-25 23:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1104 Description: The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; and 1.4.2_19 and earlier does not prevent Javascript that is loaded from the localhost from connecting to other ports on the system, which allows user-assisted attackers to bypass intended access restrictions via LiveConnect, aka CR 6724331. NOTE: this vulnerability can be leveraged with separate cross-site scripting (XSS) vulnerabilities for remote attack vectors. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_sun-java6: upstream_sun-java6: released (6.13) dapper_sun-java6: DNE gutsy_sun-java6: needs-triage (reached end-of-life) hardy_sun-java6: released (6.20dlj-0ubuntu1.8.04) intrepid_sun-java6: needs-triage (reached end-of-life) jaunty_sun-java6: released (6.20dlj-0ubuntu1.9.04) karmic_sun-java6: released (6.20dlj-0ubuntu1.9.10) lucid_sun-java6: released (6.20dlj-1ubuntu3) devel_sun-java6: DNE Patches_sun-java5: upstream_sun-java5: released (1.5.0-18) dapper_sun-java5: ignored (reached end-of-life) gutsy_sun-java5: needs-triage (reached end-of-life) hardy_sun-java5: not-affected (1.5.0-22-0ubuntu0.8.04) intrepid_sun-java5: needs-triage (reached end-of-life) jaunty_sun-java5: not-affected (1.5.0-19-0ubuntu0.9.04) karmic_sun-java5: DNE lucid_sun-java5: DNE devel_sun-java5: DNE Patches_openjdk-6: upstream_openjdk-6: not-affected (Sun Java only) dapper_openjdk-6: DNE gutsy_openjdk-6: DNE hardy_openjdk-6: not-affected (Sun Java only) intrepid_openjdk-6: not-affected (Sun Java only) jaunty_openjdk-6: not-affected (Sun Java only) karmic_openjdk-6: not-affected (Sun Java only) lucid_openjdk-6: not-affected (Sun Java only) devel_openjdk-6: not-affected (Sun Java only)