CVE-2010-1423: OS Command Injection
Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1423?
CVE-2010-1423 has a high severity rating due to its ability to allow remote code execution.
How do I fix CVE-2010-1423?
To fix CVE-2010-1423, update to the latest version of Oracle JDK or JRE that addresses this vulnerability.
What are the affected software versions for CVE-2010-1423?
CVE-2010-1423 affects Oracle JDK 6 Update 10, Update 19, and other versions up to 1.6.0.
What type of vulnerability is CVE-2010-1423?
CVE-2010-1423 is an argument injection vulnerability in the URI handler of the Java NPAPI plugin.
Can CVE-2010-1423 affect Linux users?
Yes, CVE-2010-1423 may also affect users running the vulnerable Java versions on Linux.