Upstream information
Description
The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.NVD CVSS v2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Novell Bugzilla entry: 552586, 561859 SUSE Security Advisories:- SUSE-SA:2009:058, published Thu, 19 Nov 2009 16:00:00 +0000
- SUSE-SA:2010:004, published Tue, 12 Jan 2010 17:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|
