The vulnerability is in the program for unpacking JAR archives and merely visiting a crafted website may allow the exploit. An update is available to fix the problem

[From Security vulnerability in Sun's Java environment]