Bug 581237 (CVE-2010-0886, CVE-2010-0887, CVE-2010-1423) - CVE-2010-0886 CVE-2010-0887 Sun Java: Java Web Start arbitrary command line injection
Summary: CVE-2010-0886 CVE-2010-0887 Sun Java: Java Web Start arbitrary command line i...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2010-0886, CVE-2010-0887, CVE-2010-1423
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL: http://seclists.org/fulldisclosure/20...
Whiteboard:
Depends On: 616361 616362 616394
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-04-11 10:22 UTC by Jan Lieskovsky
Modified: 2019-09-29 12:36 UTC (History)
9 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-04-11 21:37:05 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2010:0356 0 normal SHIPPED_LIVE Critical: java-1.6.0-sun security update 2010-04-19 21:20:25 UTC
Red Hat Product Errata RHSA-2010:0549 0 normal SHIPPED_LIVE Critical: java-1.6.0-ibm security update 2010-07-21 14:24:58 UTC

Description Jan Lieskovsky 2010-04-11 10:22:07 UTC
Tavis Ormandy reported:
  [1] http://seclists.org/fulldisclosure/2010/Apr/119

a deficiency in the way Java Deployment Toolkit's 
Java Web Start sanitized URL of the applications, intended
to be launched and installed via the Java Networking
Launching Protocol. Remote attacker could trick a local
victim into visiting a specially-crafted web page, potentially
leading to execution of arbitrary Java code with the
privileges of the user opening the page.

References:
  [2] http://www.reversemode.com/index.php?option=com_content&task=view&id=67&Itemid=1
  [3] http://bugs.gentoo.org/show_bug.cgi?id=314531

CVE Request:
  [4] http://www.openwall.com/lists/oss-security/2010/04/10/2

Comment 1 Andrew John Hughes 2010-04-11 22:47:09 UTC
Sun never open sourced their plugin or Web Start code so it is not part of OpenJDK/IcedTea packages.

Comment 6 errata-xmlrpc 2010-04-19 21:20:28 UTC
This issue has been addressed in following products:

  Extras for RHEL 4
  Extras for Red Hat Enterprise Linux 5

Via RHSA-2010:0356 https://rhn.redhat.com/errata/RHSA-2010-0356.html

Comment 12 errata-xmlrpc 2010-07-21 14:25:03 UTC
This issue has been addressed in following products:

  Extras for RHEL 4
  Extras for Red Hat Enterprise Linux 5

Via RHSA-2010:0549 https://rhn.redhat.com/errata/RHSA-2010-0549.html


Note You need to log in before you can comment on or make changes to this bug.