CVE-2009-3874 - CVE House
Back to Database
Status published Critical CVE-2009-3874

Integer overflow in the JPEGImageReader implementation in the ImageI/O component...

Vulnerability Description

Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug Id 6874643.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-3874

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

jdk, jre, sdk
Vulnerable Versions:
1.5.0, 1.6.0, 1.4.2_1, 1.4.2_2, 1.4.2_02, 1.4.2_03, 1.4.2_3, 1.4.2_4, 1.4.2_04, 1.4.2_05, 1.4.2_5, 1.4.2_06, 1.4.2_6, 1.4.2_7, 1.4.2_07, 1.4.2_8, 1.4.2_08, 1.4.2_09, 1.4.2_9, 1.4.2_10, 1.4.2_11, 1.4.2_12, 1.4.2_13, 1.4.2_14, 1.4.2_15, 1.4.2_16, 1.4.2_17, 1.4.2_18, 1.4.2_19, 1.4.2_20, 1.4.2_21, 1.4.2_22, 1.3.1_1, 1.3.1_01, 1.3.1_01a, 1.3.1_02, 1.3.1_2, 1.3.1_03, 1.3.1_3, 1.3.1_4, 1.3.1_04, 1.3.1_05, 1.3.1_5, 1.3.1_06, 1.3.1_6, 1.3.1_07, 1.3.1_7, 1.3.1_8, 1.3.1_08, 1.3.1_9, 1.3.1_09, 1.3.1_10, 1.3.1_11, 1.3.1_12, 1.3.1_13, 1.3.1_14, 1.3.1_15, 1.3.1_16, 1.3.1_17, 1.3.1_18, 1.3.1_19, 1.3.1_20, 1.3.1_21, 1.3.1_22, 1.3.1_23, 1.3.1_24, 1.3.1_25, 1.4.2_01

Timeline

Official Publish: November 5th, 2009
Last Modified: August 7th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.