eEye Digital Security has discovered a stack buffer overflow in Java WebStart, a utility installed with Java Runtime Environment for the purpose of managing the download of Java applications. By opening a malicious JNLP file, a user’s system may be compromised by arbitrary code within the file, which executes with the privileges of that user. Systems affected are Java Runtime Environment 6 update 1 and below and Java Runtime Environment 5 update 11 and below.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/57558/EEYE-Java.txt
Source: https://packetstormsecurity.com/files/57558/EEYE-Java.txt.html

