CVE-2009-3886 Information

Description

The Java Web Start implementation in Sun Java SE 6 before Update 17 does not properly handle the interaction between a signed JAR file and a JNLP (1) application or (2) applet which has unspecified impact and attack vectors related to a \regression\ aka Bug Id 6870531.

Reference

http://java.sun.com/javase/6/webnotes/6u17.html http://secunia.com/advisories/37386 http://security.gentoo.org/glsa/glsa-200911-02.xml https://bugzilla.redhat.com/show_bug.cgi?id=532914 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A6794

Share on: