Sun Java JRE Insecure Executable Loading Vulnerability
Last Update Date:
12 Jul 2011 12:21
Release Date:
12 Jul 2011
6419
Views
RISK: High Risk
TYPE: Operating Systems - Application Platforms
A vulnerability has identified in Sun Java, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to the application loading an executable file in an insecure manner when an out of memory condition occurs. This can be exploited to execute arbitrary programs by tricking a user into e.g. opening a HTML file, which loads an applet located on a remote WebDAV or SMB share.
Impact
- Remote Code Execution
System / Technologies affected
- Sun Java JRE 1.6.x / 6.x
Solutions
- There is no vendor supplied patch.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with