Sun Java Web Start Remote Command Execution Vulnerability
BID:31916
Info
Sun Java Web Start Remote Command Execution Vulnerability
| Bugtraq ID: | 31916 |
| Class: | Design Error |
| CVE: |
CVE-2008-4910 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2008 12:00AM |
| Updated: | Apr 16 2015 05:52PM |
| Credit: | Varun Srivastava |
| Vulnerable: |
Sun Java Web Start 1.2 Sun Java Web Start 1.0.1 _02 Sun Java Web Start 1.0.1 _01 Sun Java Web Start 1.0.1 Sun Java Web Start 1.0 Sun Java Web Start 0 |
| Not Vulnerable: | |
Discussion
Sun Java Web Start Remote Command Execution Vulnerability
Sun Java Web Start is prone to a remote command-execution vulnerability.
Successful exploits may allow attackers to execute arbitrary commands on an unsuspecting user's computer. This may aid in further attacks.
We don't know which versions of Java Web Start are affected. We will update this BID when more information is released.
Sun Java Web Start is prone to a remote command-execution vulnerability.
Successful exploits may allow attackers to execute arbitrary commands on an unsuspecting user's computer. This may aid in further attacks.
We don't know which versions of Java Web Start are affected. We will update this BID when more information is released.
Exploit / POC
Sun Java Web Start Remote Command Execution Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
Sun Java Web Start Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Sun Java Web Start Remote Command Execution Vulnerability
References:
References: