Candidate: CVE-2009-1105 PublicDate: 2009-03-25 23:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1105 Description: The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 allows user-assisted remote attackers to cause a trusted applet to run in an older JRE version, which can be used to exploit vulnerabilities in that older version, aka CR 6706490. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_sun-java6: upstream_sun-java6: released (6.13) dapper_sun-java6: DNE gutsy_sun-java6: needs-triage (reached end-of-life) hardy_sun-java6: released (6.20dlj-0ubuntu1.8.04) intrepid_sun-java6: needs-triage (reached end-of-life) jaunty_sun-java6: released (6.20dlj-0ubuntu1.9.04) karmic_sun-java6: released (6.20dlj-0ubuntu1.9.10) lucid_sun-java6: released (6.20dlj-1ubuntu3) devel_sun-java6: DNE Patches_sun-java5: upstream_sun-java5: not-affected dapper_sun-java5: ignored (reached end-of-life) gutsy_sun-java5: needs-triage (reached end-of-life) hardy_sun-java5: not-affected (1.5.0-22-0ubuntu0.8.04) intrepid_sun-java5: needs-triage (reached end-of-life) jaunty_sun-java5: not-affected (1.5.0-19-0ubuntu0.9.04) karmic_sun-java5: DNE lucid_sun-java5: DNE devel_sun-java5: DNE Patches_openjdk-6: upstream_openjdk-6: not-affected (Sun Java only) dapper_openjdk-6: DNE gutsy_openjdk-6: DNE hardy_openjdk-6: not-affected (Sun Java only) intrepid_openjdk-6: not-affected (Sun Java only) jaunty_openjdk-6: not-affected (Sun Java only) karmic_openjdk-6: not-affected (Sun Java only) lucid_openjdk-6: not-affected (Sun Java only) devel_openjdk-6: not-affected (Sun Java only)