First published: Wed Nov 04 2009(Updated: )
Mentioned at <a href="http://java.sun.com/javase/6/webnotes/6u17.html">http://java.sun.com/javase/6/webnotes/6u17.html</a> no other details
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sun JRE | =1.6.0-update_3 | |
Sun JRE | =1.6.0-update_5 | |
Sun JRE | =1.6.0-update_13 | |
Sun JRE | =1.6.0-update_1 | |
Sun JRE | =1.6.0-update_2 | |
Sun JRE | =1.6.0-update_15 | |
Sun JRE | =1.6.0-update_6 | |
Sun JRE | =1.6.0-update_10 | |
Sun JRE | =1.6.0-update_8 | |
Sun JRE | =1.6.0-update_7 | |
Sun JRE | =1.6.0-update_14 | |
Sun JRE | <=1.6.0 | |
Sun JRE | =1.6.0-update_4 | |
Sun JRE | =1.6.0-update_9 | |
Sun JRE | =1.6.0-update_12 | |
Sun JRE | =1.6.0-update_11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3886 is categorized as a high severity vulnerability due to its ability to exploit the interaction between signed JAR files and JNLP applications.
To mitigate CVE-2009-3886, upgrade to Sun Java SE 6 Update 17 or later versions.
CVE-2009-3886 affects multiple versions of Sun Java Runtime Environment 1.6.0, specifically from update 1 through update 16.
CVE-2009-3886 is a vulnerability in the Java Web Start implementation that can lead to unauthorized actions via manipulated JAR files.
There are no specific workarounds for CVE-2009-3886; updating the JRE is the recommended solution.