← Back

CVE-2009-1190

nvd nist
Published: Apr 27, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.

Affected (139)

Products: Sun: Jdk
1 product
Jdk
Configuration A
139 vulnerable · 34 platform
Vulnerable SoftwareAffected Versions
Sun
Up to 1.5.0
Version 1.1.0
Version 1.1.6
Version 1.1.6 update7
Version 1.1.7b
Version 1.1.7b update5
Version 1.1.8 update10
Version 1.1.8 update13
Version 1.1.8 update14
Version 1.1.8 update2
Version 1.1.8 update7
Version 1.1.8 update8
Version 1.2.0
Version 1.2.1
Version 1.2.1 update3
Version 1.2.2 update4
Version 1.2.2 update5
Version 1.3.0
Version 1.3.0_01
Version 1.3.0_02
Version 1.3.0_03
Version 1.3.0_04
Version 1.3.0_05
Version 1.3.1
Version 1.3.1 update19
Version 1.3.1 update20
Version 1.3.1_01
Version 1.3.1_01a
Version 1.3.1_02
Version 1.3.1_03
Version 1.3.1_04
Version 1.3.1_05
Version 1.3.1_06
Version 1.3.1_07
Version 1.3.1_08
Version 1.3.1_09
Version 1.3.1_10
Version 1.3.1_11
Version 1.3.1_12
Version 1.3.1_13
Version 1.3.1_14
Version 1.3.1_15
Version 1.3.1_16
Version 1.3.1_17
Version 1.3.1_18
Version 1.3.1_19
Version 1.3.1_20
Version 1.3.1_21
Version 1.3.1_22
Version 1.3.1_23
Version 1.3.1_24
Version 1.3.1_25
Version 1.3.1_26
Version 1.3.1_27
Version 1.3.1_28
Version 1.4.0
Version 1.4.0_01
Version 1.4.0_02
Version 1.4.0_03
Version 1.4.0_04
Version 1.4.1
Version 1.4.1_01
Version 1.4.1_02
Version 1.4.1_03
Version 1.4.1_04
Version 1.4.1_05
Version 1.4.1_06
Version 1.4.1_07
Version 1.4.2
Version 1.4.2_10
Version 1.4.2_11
Version 1.4.2_12
Version 1.4.2_13
Version 1.4.2_14
Version 1.4.2_15
Version 1.4.2_16
Version 1.4.2_17
Version 1.4.2_18
Version 1.4.2_19
Version 1.4.2_1
Version 1.4.2_2
Version 1.4.2_3
Version 1.4.2_4
Version 1.4.2_5
Version 1.4.2_6
Version 1.4.2_7
Version 1.4.2_8
Version 1.4.2_9
Version 1.5.0
Version 1.5.0 update10
Version 1.5.0 update11
Version 1.5.0 update11_b03
Version 1.5.0 update12
Version 1.5.0 update13
Version 1.5.0 update14
Version 1.5.0 update15
Version 1.5.0 update16
Version 1.5.0 update17
Version 1.5.0 update18
Version 1.5.0 update19
Version 1.5.0 update1
Version 1.5.0 update20
Version 1.5.0 update21
Version 1.5.0 update22
Version 1.5.0 update23
Version 1.5.0 update24
Version 1.5.0 update25
Version 1.5.0 update2
Version 1.5.0 update3
Version 1.5.0 update4
Version 1.5.0 update5
Version 1.5.0 update6
Version 1.5.0 update7
Version 1.5.0 update7_b03
Version 1.5.0 update8
Version 1.5.0 update9
Version 1.5.0 update_10
Version 1.5.0 update_11
Version 1.5.0 update_12
Version 1.5.0 update_13
Version 1.5.0 update_14
Version 1.5.0 update_15
Version 1.5.0 update_16
Version 1.5.0 update_17
Version 1.5.0 update_18
Version 1.5.0 update_19
Version 1.5.0 update_1
Version 1.5.0 update_20
Version 1.5.0 update_21
Version 1.5.0 update_2
Version 1.5.0 update_3
Version 1.5.0 update_4
Version 1.5.0 update_5
Version 1.5.0 update_6
Version 1.5.0 update_7
Version 1.5.0 update_8
Version 1.5.0 update_9
Version 1.5.0_03
Version 1.5.0_03
Running on/withPlatform Versions
Springsource
Dm Server
Version 1.0.0
Springsource
Dm Server
Version 1.0.1
Springsource
Dm Server
Version 1.0.2
Springsource
Spring Framework
Version 1.1.0
Springsource
Spring Framework
Version 2.0.1
Springsource
Spring Framework
Version 2.0.2
Springsource
Spring Framework
Version 2.0.3
Springsource
Spring Framework
Version 2.0.4
Springsource
Spring Framework
Version 2.0.5
Springsource
Spring Framework
Version 2.0
Springsource
Spring Framework
Version 2.0 m1
Springsource
Spring Framework
Version 2.0 m2
Springsource
Spring Framework
Version 2.0 m3
Springsource
Spring Framework
Version 2.0 m4
Springsource
Spring Framework
Version 2.0 m5
Springsource
Spring Framework
Version 2.0 rc1
Springsource
Spring Framework
Version 2.0 rc2
Springsource
Spring Framework
Version 2.0 rc3
Springsource
Spring Framework
Version 2.0 rc4
Springsource
Spring Framework
Version 2.1 m1
Springsource
Spring Framework
Version 2.1 m2
Springsource
Spring Framework
Version 2.1 m3
Springsource
Spring Framework
Version 2.1 m4
Springsource
Spring Framework
Version 2.5.0
Springsource
Spring Framework
Version 2.5.0 rc1
Springsource
Spring Framework
Version 2.5.0 rc2
Springsource
Spring Framework
Version 2.5.1
Springsource
Spring Framework
Version 2.5.2
Springsource
Spring Framework
Version 2.5.3
Springsource
Spring Framework
Version 2.5.4
Springsource
Spring Framework
Version 2.5.5
Springsource
Spring Framework
Version 2.5.6
Springsource
Spring Framework
Version 3.0.0 m1
Springsource
Spring Framework
Version 3.0.0 m2

Related CWEs

References (12)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.