Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3865 to the following vulnerability: The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752. References: ----------- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3865 http://java.sun.com/javase/6/webnotes/6u17.html http://sunsolve.sun.com/search/document.do?assetkey=1-66-269869-1 http://www.securityfocus.com/bid/36881 http://secunia.com/advisories/37231 http://www.vupen.com/english/advisories/2009/3131
This issue does NOT affect the versions of the java-1.5.0-sun package, as shipped with Red Hat Enterprise Linux 4 and 5. This issue affects the versions of the java-1.6.0-sun package, as shipped with Red Hat Enterprise Linux 4 and 5.
*** Bug 532910 has been marked as a duplicate of this bug. ***
This issue has been addressed in following products: Extras for RHEL 4 Extras for Red Hat Enterprise Linux 5 Via RHSA-2009:1560 https://rhn.redhat.com/errata/RHSA-2009-1560.html
This issue has been addressed in following products: Extras for RHEL 4 Extras for Red Hat Enterprise Linux 5 Via RHSA-2009:1694 https://rhn.redhat.com/errata/RHSA-2009-1694.html
This issue has been addressed in following products: Red Hat Network Satellite Server v 5.3 Via RHSA-2010:0043 https://rhn.redhat.com/errata/RHSA-2010-0043.html