Product: Java Platform, Standard Edition (Java SE)

A security vulnerability in the JNLPAppletLauncher may impact users of the Sun JDK and JRE. Non-current versions of the JNLPAppletLauncher may be re-purposed with an untrusted Java applet to write arbitrary files on the system of the user downloading and running the untrusted applet.

The JNLPAppletLauncher is a general purpose JNLP-based applet launcher class for deploying applets that use extension libraries containing native code.

For more information about JNLPAppletlauncher, see https://applet-launcher.dev.java.net/

Sun acknowledges with thanks, John Heasman for bringing this issue to our attention.

State: Resolved
First released: 04-Aug-2009
Permalink |

Comments:

Post a Comment:

Comments are closed for this entry.