Red Hat Bugzilla – Bug 454606
CVE-2008-3112 Java Web Start, arbitrary file creation (6703909)
Last modified: 2013-03-26 12:05:44 EDT
Sunalert, 238905, Second Issue A vulnerability in Java Web Start may allow an untrusted Java Web Start application downloaded from a website to create arbitrary files with the permissions of the user running the untrusted Java Web Start application.
This was resolved via: http://rhn.redhat.com/errata/RHSA-2008-0595.html (RHEL4, RHEL5) http://rhn.redhat.com/errata/RHSA-2008-0955.html (RHEL3, RHEL4, RHEL5) http://rhn.redhat.com/errata/RHSA-2008-0790.html (RHEL4, RHEL5) http://rhn.redhat.com/errata/RHSA-2008-0636.html (Satellite 5.1) http://rhn.redhat.com/errata/RHSA-2008-0638.html (Satellite 5.1) http://rhn.redhat.com/errata/RHSA-2008-0906.html (RHEL4, RHEL5) http://rhn.redhat.com/errata/RHSA-2008-0594.html (RHEL4, RHEL5)