CVE-2009-3866
published 2009-11-05CVE-2009-3866: The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer…
PriorityP348critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.18%
92.7th percentile
The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-768x-w4jc-f2gp: The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer
ghsa_unreviewed·2022-05-02
CVE-2009-3866 [HIGH] GHSA-768x-w4jc-f2gp: The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer
The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.
Red Hat
java-1.6.0-sun: Privilege escalation in the Java Web Start Installer (6872824)
vendor_redhat·2009-11-03·CVSS 9.3
CVE-2009-3866 [CRITICAL] java-1.6.0-sun: Privilege escalation in the Java Web Start Installer (6872824)
java-1.6.0-sun: Privilege escalation in the Java Web Start Installer (6872824)
The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3866 java-1.6.0-sun: Privilege escalation in the Java Web Start Installer (6872824)
bugzilla·2009-11-05·CVSS 9.3
CVE-2009-3866 [CRITICAL] CVE-2009-3866 java-1.6.0-sun: Privilege escalation in the Java Web Start Installer (6872824)
CVE-2009-3866 java-1.6.0-sun: Privilege escalation in the Java Web Start Installer (6872824)
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3866 to
the following vulnerability:
The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before
Update 17 does not properly use security model permissions when
removing installer extensions, which allows remote attackers to
execute arbitrary code by modifying a certain JNLP file to have a URL
field that points to an unintended trusted application, aka Bug Id
6872824.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3866
http://zerodayinitiative.com/advisories/ZDI-09-077/
http://java.sun.com/javase/6/webnotes/6u17.html
http://sunsolve.sun.com/search/document.do?assetkey=1-66-269870-1
http://www.securit
Bugzilla
CVE-2009-3866 JRE arbitary code execution using java web start (6872824)
bugzilla·2009-11-04·CVSS 9.3
CVE-2009-3866 [CRITICAL] CVE-2009-3866 JRE arbitary code execution using java web start (6872824)
CVE-2009-3866 JRE arbitary code execution using java web start (6872824)
aka http://sunsolve.sun.com/search/document.do?assetkey=1-66-269870-1
A security vulnerability in the Java Web Start Installer may be
leveraged to allow an untrusted Java Web Start application to run as a trusted
application and execute arbitrary code. This may occur when a user opens a
specially crafted web page that exploits this vulnerability.
Discussion:
*** This bug has been marked as a duplicate of bug 533212 ***
http://java.sun.com/javase/6/webnotes/6u17.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.htmlhttp://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/37231http://secunia.com/advisories/37239http://secunia.com/advisories/37386http://secunia.com/advisories/37581http://secunia.com/advisories/37841http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-269870-1http://support.apple.com/kb/HT3969http://support.apple.com/kb/HT3970http://www.redhat.com/support/errata/RHSA-2009-1694.htmlhttp://www.securityfocus.com/bid/36881http://www.vupen.com/english/advisories/2009/3131http://zerodayinitiative.com/advisories/ZDI-09-077/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6635http://java.sun.com/javase/6/webnotes/6u17.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Dec/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00010.htmlhttp://marc.info/?l=bugtraq&m=134254866602253&w=2http://secunia.com/advisories/37231http://secunia.com/advisories/37239http://secunia.com/advisories/37386http://secunia.com/advisories/37581http://secunia.com/advisories/37841http://security.gentoo.org/glsa/glsa-200911-02.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-269870-1http://support.apple.com/kb/HT3969http://support.apple.com/kb/HT3970http://www.redhat.com/support/errata/RHSA-2009-1694.htmlhttp://www.securityfocus.com/bid/36881http://www.vupen.com/english/advisories/2009/3131http://zerodayinitiative.com/advisories/ZDI-09-077/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6635
2009-11-05
Published