CVE-2009-3866

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.

References

http://java.sun.com/javase/6/webnotes/6u17.html

http://lists.apple.com/archives/security-announce/2009/Dec/msg00000.html

http://lists.apple.com/archives/security-announce/2009/Dec/msg00001.html

http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.html

http://marc.info/?l=bugtraq&m=134254866602253&w=2

http://secunia.com/advisories/37231

http://secunia.com/advisories/37239

http://secunia.com/advisories/37386

http://secunia.com/advisories/37581

http://secunia.com/advisories/37841

http://security.gentoo.org/glsa/glsa-200911-02.xml

http://sunsolve.sun.com/search/document.do?assetkey=1-66-269870-1

http://support.apple.com/kb/HT3969

http://support.apple.com/kb/HT3970

http://www.redhat.com/support/errata/RHSA-2009-1694.html

http://www.securityfocus.com/bid/36881

http://www.vupen.com/english/advisories/2009/3131

http://zerodayinitiative.com/advisories/ZDI-09-077/

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6635

Details

Source: MITRE

Published: 2009-11-05

Updated: 2017-09-19

Type: CWE-264

Risk Information

CVSS v2

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

Tenable Plugins

View all (16 total)

IDNameProductFamilySeverity
89736VMware ESX Java Runtime Environment (JRE) Multiple Vulnerabilities (VMSA-2010-0002) (remote check)NessusVMware ESX Local Security Checks
critical
64831Sun Java JRE Multiple Vulnerabilities (269868 / 269869 / 270476 ...) (Unix)NessusMisc.
high
60691Scientific Linux Security Update : java (jdk 1.6.0) on SL4.x, SL5.x i386/x86_64NessusScientific Linux Local Security Checks
high
45386VMSA-2010-0002 : VMware vCenter update release addresses multiple security issues in Java JRENessusVMware ESX Local Security Checks
critical
44029RHEL 4 / 5 : IBM Java Runtime in Satellite Server (RHSA-2010:0043)NessusRed Hat Local Security Checks
critical
43872SuSE 11 Security Update : IBM Java 1.6.0 (SAT Patch Number 1748)NessusSuSE Local Security Checks
high
43597RHEL 4 / 5 : java-1.6.0-ibm (RHSA-2009:1694)NessusRed Hat Local Security Checks
critical
43003Mac OS X : Java for Mac OS X 10.6 Update 1NessusMacOS X Local Security Checks
high
43002Mac OS X : Java for Mac OS X 10.5 Update 6NessusMacOS X Local Security Checks
high
42857SuSE 11 Security Update : Sun Java 1.6.0 (SAT Patch Number 1542)NessusSuSE Local Security Checks
high
42855openSUSE Security Update : java-1_6_0-sun (java-1_6_0-sun-1541)NessusSuSE Local Security Checks
high
42853openSUSE Security Update : java-1_6_0-sun (java-1_6_0-sun-1541)NessusSuSE Local Security Checks
high
42851openSUSE Security Update : java-1_6_0-sun (java-1_6_0-sun-1541)NessusSuSE Local Security Checks
high
42834GLSA-200911-02 : Sun JDK/JRE: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
42431RHEL 4 / 5 : java-1.6.0-sun (RHSA-2009:1560)NessusRed Hat Local Security Checks
critical
42373Sun Java JRE Multiple Vulnerabilities (269868 / 269869 / 270476 ..)NessusWindows
high