java-1.6.0-sun: ACE in JRE Deployment Toolkit (6869752)
Published Nov 5, 2009
9.3
HIGHCVSS 2.0
EPSS 9.40%
Description
The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752.
Affected products
No data.
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
No data.
Extras for RHEL 4
java-1.6.0-ibm-1:1.6.0.7-1jpp.3.el4
Fixed · RHSA-2009:1694
Extras for RHEL 4
java-1.6.0-sun-1:1.6.0.17-1jpp.1.el4
Fixed · RHSA-2009:1560
Red Hat Network Satellite Server v 5.3
java-1.6.0-ibm-1:1.6.0.7-1jpp.2.el5
Fixed · RHSA-2010:0043
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-ibm-1:1.6.0.7-1jpp.2.el5
Fixed · RHSA-2009:1694
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.17-1jpp.2.el5
Fixed · RHSA-2009:1560
| Product | Package | State | Advisory |
|---|---|---|---|
| Extras for RHEL 4 | java-1.6.0-ibm-1:1.6.0.7-1jpp.3.el4 | Fixed | RHSA-2009:1694 |
| Extras for RHEL 4 | java-1.6.0-sun-1:1.6.0.17-1jpp.1.el4 | Fixed | RHSA-2009:1560 |
| Red Hat Network Satellite Server v 5.3 | java-1.6.0-ibm-1:1.6.0.7-1jpp.2.el5 | Fixed | RHSA-2010:0043 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-ibm-1:1.6.0.7-1jpp.2.el5 | Fixed | RHSA-2009:1694 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.17-1jpp.2.el5 | Fixed | RHSA-2009:1560 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (24)
- http://java.sun.com/javase/6/webnotes/6u17.html x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2009/Dec/msg00000.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2009/Dec/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=134254866602253&w=2 vendor-advisoryx_refsource_HP
- http://secunia.com/advisories/37231 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/37239 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/37386 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/37581 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/37841 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200911-02.xml vendor-advisoryx_refsource_GENTOO
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-269869-1 vendor-advisoryx_refsource_SUNALERTPatchVendor Advisory
- http://support.apple.com/kb/HT3969 x_refsource_CONFIRM
- http://support.apple.com/kb/HT3970 x_refsource_CONFIRM
- http://www.redhat.com/support/errata/RHSA-2009-1694.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/36881 vdb-entryx_refsource_BIDPatch
- http://www.securitytracker.com/id?1023244 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2009/3131 vdb-entryx_refsource_VUPENPatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-3865 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=533211 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-3836 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-3865
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7562 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-3865
Change history (0)
No recorded changes yet.