HTTP: Sun Java HsbParser.getSoundBank Stack Buffer Overflow

This signature detects attempts to exploit a known vulnerability in Sun Java. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

Sun has released updates to address multiple security vulnerabilities in Java SE. Successful exploits may allow attackers to bypass certain security restrictions, run untrusted applets with elevated privileges, execute arbitrary code, and cause denial-of-service conditions. Other attacks are also possible. These issues are addressed in the following releases: JDK and JRE 6 Update 17 JDK and JRE 5.0 Update 22 SDK and JRE 1.4.2_24 SDK and JRE 1.3.1_27

Affected Products

Hp network_node_manager_i

References

BugTraq: 36881

CVE: CVE-2009-3867

Short Name
HTTP:STC:JAVA:GETSOUNDBANK-OF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Buffer CVE-2009-3867 HsbParser.getSoundBank Java Overflow Stack Sun bid:36881
Release Date
07/18/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
False Positive
Unknown
Vendors

Red_hat

Suse

Apple

Gentoo

Sun

Hp

Avaya

Mandriva

Rpath

Pardus

Ubuntu

Oracle

Panda

Vmware

Ibm

CVSS Score

9.3

Found a potential security threat?