The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2009-05-18T18:00:00
Updated: 2024-08-07T05:20:35.173Z
Reserved: 2009-05-18T00:00:00
Link: CVE-2009-1672
Vulnrichment
No data.
NVD
Status : Modified
Published: 2009-05-18T18:30:01.047
Modified: 2024-11-21T01:03:02.980
Link: CVE-2009-1672
Redhat
No data.