PT-2009-4156 · Sun · Sun Java Runtime Environment

Shinnai

·

Publicado

2009-05-18

·

Atualizado

2024-02-14

·

CVE-2009-1672

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Sun Java SE Runtime Environment (JRE) 6 Update 13
Description: The issue allows remote attackers to execute arbitrary code via a .jnlp URL in the argument to the launch method. Additionally, it might allow remote attackers to launch JRE installation processes via the installLatestJRE or installJRE method.
Recommendations: For Sun Java SE Runtime Environment (JRE) 6 Update 13, consider disabling the deploytk.dll ActiveX control until a patch is available. Restrict access to the launch, installLatestJRE, and installJRE methods to minimize the risk of exploitation. Avoid using the .jnlp URL in the launch method argument until the issue is resolved.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-1672

Produtos afetados

Sun Java Runtime Environment