This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Sun Java Plugin...vuln/fix Available!

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.idefense.com/application/poi/di…lashstatus=true
"iDEFENSE Security Advisory 11.22.04:
…II. DESCRIPTION
Remote exploitation of a design vulnerability in Sun Microsystems Inc.'s Java Plug-in technology allows attackers to bypass the Java sandbox and all security restrictions imposed within Java Applets…
III. ANALYSIS
Successful exploitation allows remote attackers to execute hostile Applets that can access, download, upload or execute arbitrary files as well as access the network. A target user must be running a browser on top of a vulnerable Java Virtual Machine to be affected. It is possible for an attacker to create a cross-platform, cross-browser exploit for this vulnerability. Once compromised, an attacker can execute arbitrary code under the privileges of the user who instantiated the vulnerable browser.
IV. DETECTION
iDEFENSE has confirmed the existence of this vulnerability in Java 2 Platform, Standard Edition (J2SE) 1.4.2_01 and 1.4.2_04 from Sun Microsystems. It is suspected that earlier versions are vulnerable as well. Various browsers such as Internet Explorer, Mozilla and Firefox on both Windows and Unix platforms can be exploited if they are running a vulnerable Java Virtual Machine.
V. WORKAROUND
Disabling Java or JavaScript will prevent exploitation as the vulnerability relies on the data transfer between the two components. Other Java Virtual Machines, such as the Microsoft VM, are available and can be used as an alternative.
VI. VENDOR RESPONSE
>>> This issue has been fixed in J2SE v 1.4.2_06 available at: http://java.sun.com/j2se/1.4.2/download.html …"

(Caution to dial-up users: This is a 15.3MB download - find a friend with DSL or cable!) :blink:
FYI…

New Multi-Platform, MultiBrowser Java/JavaScript Vulnerability
- http://isc.sans.org/diary.php?date=2004-11-23
Updated November 24th 2004 14:00 UTC
"This one is now public and it looks like it could be a biggie. Consider this your "heads up."

There is an issue with Sun's Java Virtual Machine (VM) in versions less than 1.4.2_06 that allows access, via JavaScript, to portions of a browser's Java plug-in that should NOT be available to untrusted applets. In order to understand what's going on here, you need to understand a little about how Java applets work. Most people know Java as a cross-platform language for writing web based "applets" – small programs that run within a web browser in what is known as a "sandbox" environment. This sandbox allows "applets" to perform a specific set of actions that are deemed "safe", and keeps it from being able to do Evil things to your machine (installing viruses, formatting your hard drive, transferring money from your bank account into the ISC Handler's slush fund, etc…). In order for Java applets to do their thing, however, the "plug-in" (the part of the browser that actually runs the applets) has to have some capabilities that you would never trust to an applet. All that stands in the way are the rules that limit what an "applet" is allowed to do within the plug-in itself. It is these rules that constitute the Java "sandbox."
So now we need to worry about malicious Java "applets" (with a little help from JavaScript) jumping beyond the sandbox and running around saying things like "quid pro quo" and serving up our PCs with a generous helping of fava beans.

What to do? Patch!…You want to make sure that you're running a plug-in that is version 1.4.2_06 or greater. Updated versions are available here:
- http://java.sun.com/j2se/1.4.2/download.html …" :blink: