Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allow remote attackers to execute arbitrary code via a crafted jnlp file that modifies the (1) java.home, (2) java.ext.dirs, or (3) user.home System Properties, aka "Java Web Start File Inclusion" and CR 6694892.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2008-12-05T02:00:00
Updated: 2018-10-11T19:57:01
Reserved: 2008-05-06T00:00:00
Link: CVE-2008-2086
JSON object: View
NVD Information
Status : Modified
Published: 2008-12-05T02:30:00.190
Modified: 2018-10-11T20:39:11.047
Link: CVE-2008-2086
JSON object: View
Redhat Information
No data.
CWE