Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-3866

Опубликовано: 03 нояб. 2009
Источник: redhat
CVSS2: 6.8

Описание

The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=533212java-1.6.0-sun: Privilege escalation in the Java Web Start Installer (6872824)

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 16 лет назад

The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.

nvd
около 16 лет назад

The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.

debian
около 16 лет назад

The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Up ...

github
больше 3 лет назад

The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.

6.8 Medium

CVSS2