The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on X11 does not impose the intended constraint on distance from the window border to the Security Warning Icon, which makes it easier for context-dependent attackers to trick a user into interacting unsafely with an untrusted applet.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/37460 | third party advisory |
http://security.gentoo.org/glsa/glsa-200911-02.xml | vendor advisory |
http://www.vmware.com/security/advisories/VMSA-2009-0016.html | |
http://java.sun.com/javase/6/webnotes/6u15.html | |
http://www.securityfocus.com/archive/1/507985/100/0/threaded | mailing list |
http://secunia.com/advisories/37386 | third party advisory |
http://www.vupen.com/english/advisories/2009/3316 | vdb entry |