Overview
A vulnerability in the Sun Java Runtime Environment may allow an attacker to execute arbitrary code on a vulnerable system.
Description
The Sun Java Runtime Environment (JRE) allows users to run Java applications in a browser or as standalone programs. Sun has made the JRE available for multiple operating systems. Per Sunsolve Document ID 102729: |
Impact
A remote unauthenticated attacker may be able to execute arbitrary code. |
Solution
Upgrade Sun has released an upgrade to address this issue. See Sunsolve Document ID 102729 for more details. To adjust the JRE update settings, see the update section of the Java deployment guide. |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://secunia.com/advisories/23445/
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102729-1
- http://scary.beasts.org/security/CESA-2005-008.txt
- http://secunia.com/advisories/23803/
- http://java.sun.com/j2se/1.5.0/docs/guide/deployment/deployment-guide/jcp.html#update
- http://secunia.com/advisories/23835/
- http://www.securityfocus.com/bid/21675
- http://secunia.com/advisories/24189/
Acknowledgements
Sun thanks Chris Evans for reporting this vulnerability.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2006-6731 |
Severity Metric: | 8.53 |
Date Public: | 2006-12-20 |
Date First Published: | 2007-01-09 |
Date Last Updated: | 2007-02-20 15:01 UTC |
Document Revision: | 48 |