First published: Thu Nov 05 2009(Updated: )
The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun JDK | =1.6.0-update_4 | |
Sun JRE | =1.6.0-update_3 | |
Sun JRE | =1.6.0-update_5 | |
Sun JDK | =1.6.0-update_7 | |
Sun JDK | =1.6.0-update_13 | |
Sun JRE | =1.6.0-update_13 | |
Sun JDK | =1.6.0-update_9 | |
Sun JRE | =1.6.0-update_1 | |
Sun JRE | =1.6.0-update_2 | |
Sun JDK | =1.6.0-update_3 | |
Sun JRE | =1.6.0-update_16 | |
Sun JDK | =1.6.0-update_11 | |
Sun JDK | =1.6.0-update_10 | |
Sun JRE | =1.6.0-update_15 | |
Sun JRE | =1.6.0-update_6 | |
Sun JDK | =1.6.0-update_14 | |
Sun JDK | =1.6.0-update_5 | |
Sun JDK | =1.6.0-update_8 | |
Sun JRE | =1.6.0-update_10 | |
Sun JDK | =1.6.0-update_16 | |
Sun JRE | =1.6.0-update_8 | |
Sun JRE | =1.6.0-update_7 | |
Sun JRE | =1.6.0-update_14 | |
Sun JDK | =1.6.0-update_15 | |
Sun JDK | =1.6.0-update_12 | |
Sun JRE | =1.6.0-update_4 | |
Sun JDK | =1.6.0-update_1 | |
Sun JDK | =1.6.0-update_6 | |
Sun JRE | =1.6.0-update_9 | |
Sun JRE | =1.6.0-update_12 | |
Sun JRE | =1.6.0-update_11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.