Java SE 6 Update 31 and Java SE 7 Update 3 of Oracle/Sun Java fixes an unspecified vulnerability in the Deployment component (CVE-2012-0499). Upstream has CVSSv2 scored this issue as: 10/AV:N/AC:L/Au:N/C:C/I:C/A:C http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html
TELUS Security Labs VR advisory for this issue: http://seclists.org/fulldisclosure/2012/Feb/251 http://telussecuritylabs.com/threats/show/TSL20120214-01
This issue has been addressed in following products: Extras for RHEL 4 Supplementary for Red Hat Enterprise Linux 5 Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2012:0139 https://rhn.redhat.com/errata/RHSA-2012-0139.html
(In reply to comment #1) > TELUS Security Labs VR advisory for this issue: > > http://seclists.org/fulldisclosure/2012/Feb/251 > http://telussecuritylabs.com/threats/show/TSL20120214-01 This advisory now links ZDI-12-037 and ZDI-12-039: Oracle Java Web Start JNLP Double Quote Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-12-037/ Oracle Java Web Start java-vm-args Command Argument Injection Remote Code Execution http://www.zerodayinitiative.com/advisories/ZDI-12-039/
This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 5 Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2012:0514 https://rhn.redhat.com/errata/RHSA-2012-0514.html
(In reply to comment #7) > Oracle Java Web Start JNLP Double Quote Remote Code Execution Vulnerability > http://www.zerodayinitiative.com/advisories/ZDI-12-037/ > > Oracle Java Web Start java-vm-args Command Argument Injection Remote Code > Execution > http://www.zerodayinitiative.com/advisories/ZDI-12-039/ Also confirmed now by: http://www.attrition.org/pipermail/vim/2012-June/002572.html
This issue has been addressed in following products: Red Hat Network Satellite Server v 5.4 Via RHSA-2013:1455 https://rhn.redhat.com/errata/RHSA-2013-1455.html