The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jdk | Sun | 1.6.0-update1 (including) | 1.6.0-update1 (including) |
Jdk | Sun | 1.6.0-update1_b06 (including) | 1.6.0-update1_b06 (including) |
Jdk | Sun | 1.6.0-update10 (including) | 1.6.0-update10 (including) |
Jdk | Sun | 1.6.0-update11 (including) | 1.6.0-update11 (including) |
Jdk | Sun | 1.6.0-update12 (including) | 1.6.0-update12 (including) |
Jdk | Sun | 1.6.0-update13 (including) | 1.6.0-update13 (including) |
Jdk | Sun | 1.6.0-update14 (including) | 1.6.0-update14 (including) |
Jdk | Sun | 1.6.0-update15 (including) | 1.6.0-update15 (including) |
Jdk | Sun | 1.6.0-update16 (including) | 1.6.0-update16 (including) |
Jdk | Sun | 1.6.0-update2 (including) | 1.6.0-update2 (including) |
Jdk | Sun | 1.6.0-update3 (including) | 1.6.0-update3 (including) |
Jdk | Sun | 1.6.0-update4 (including) | 1.6.0-update4 (including) |
Jdk | Sun | 1.6.0-update5 (including) | 1.6.0-update5 (including) |
Jdk | Sun | 1.6.0-update6 (including) | 1.6.0-update6 (including) |
Jdk | Sun | 1.6.0-update7 (including) | 1.6.0-update7 (including) |
Jdk | Sun | 1.6.0-update8 (including) | 1.6.0-update8 (including) |
Jdk | Sun | 1.6.0-update9 (including) | 1.6.0-update9 (including) |
Jre | Sun | 1.6.0-update_1 (including) | 1.6.0-update_1 (including) |
Jre | Sun | 1.6.0-update_2 (including) | 1.6.0-update_2 (including) |
Jre | Sun | 1.6.0-update_3 (including) | 1.6.0-update_3 (including) |
Jre | Sun | 1.6.0-update10 (including) | 1.6.0-update10 (including) |
Jre | Sun | 1.6.0-update11 (including) | 1.6.0-update11 (including) |
Jre | Sun | 1.6.0-update12 (including) | 1.6.0-update12 (including) |
Jre | Sun | 1.6.0-update13 (including) | 1.6.0-update13 (including) |
Jre | Sun | 1.6.0-update14 (including) | 1.6.0-update14 (including) |
Jre | Sun | 1.6.0-update15 (including) | 1.6.0-update15 (including) |
Jre | Sun | 1.6.0-update16 (including) | 1.6.0-update16 (including) |
Jre | Sun | 1.6.0-update4 (including) | 1.6.0-update4 (including) |
Jre | Sun | 1.6.0-update5 (including) | 1.6.0-update5 (including) |
Jre | Sun | 1.6.0-update6 (including) | 1.6.0-update6 (including) |
Jre | Sun | 1.6.0-update7 (including) | 1.6.0-update7 (including) |
Jre | Sun | 1.6.0-update8 (including) | 1.6.0-update8 (including) |
Jre | Sun | 1.6.0-update9 (including) | 1.6.0-update9 (including) |
Extras for RHEL 4 | RedHat | java-1.6.0-sun-1:1.6.0.17-1jpp.1.el4 | * |
Extras for RHEL 4 | RedHat | java-1.6.0-ibm-1:1.6.0.7-1jpp.3.el4 | * |
Red Hat Network Satellite Server v 5.3 | RedHat | java-1.6.0-ibm-1:1.6.0.7-1jpp.2.el5 | * |
Supplementary for Red Hat Enterprise Linux 5 | RedHat | java-1.6.0-sun-1:1.6.0.17-1jpp.2.el5 | * |
Supplementary for Red Hat Enterprise Linux 5 | RedHat | java-1.6.0-ibm-1:1.6.0.7-1jpp.2.el5 | * |
Sun-java6 | Ubuntu | hardy | * |
Sun-java6 | Ubuntu | intrepid | * |
Sun-java6 | Ubuntu | jaunty | * |
Sun-java6 | Ubuntu | karmic | * |
Sun-java6 | Ubuntu | lucid | * |
Sun-java6 | Ubuntu | upstream | * |