This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Java Webstart Cross Platform Vuln/upgr Available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?date=2005-03-18
Updated March 19th 2005 00:16 UTC
"Systems running Java J2SE 1.4.2_06 and earlier 1.4.2 releases have been determined to be vulnerable to a malicious JNLP file, resulting in an untrusted application being able to elevate its privileges and escape the restricted environment. This affects browsers (and other applications using "javaws") on Windows, Linux, and Solaris, and could lead to a cross-platform worm. Solutions are to upgrade the J2SE environment, or disable "application/x-java-jnlp-file" JNLP handlers within your web browsers. According to the discoverer, Jouko Pynnonen, versions of J2SE prior to 1.4.2 (eg; the 1.3 and earlier 1.4 series) are not vulnerable to this attack. A proof of concept has been released, and overall impact is similar to the recent IFRAME attack, so it is likely that we'll see this one in the wild…"

- http://www.k-otik.com/english/advisories/2005/0282

- http://sunsolve.sun.com/search/document.do…ey=1-26-57740-1
"…Resolution This issue is addressed in Java Web Start in the following J2SE releases:
* 1.4.2_07 or later for Windows, Solaris and Linux …"

>>> http://java.sun.com/j2se/1.4.2/download.html
"…Note: It is recommended that affected versions be removed from your system. For more information, please see the installation notes on the respective java.sun.com download pages."
(Most users will -not- need the "J2SE Software Development Kit (SDK)" and should
download the "J2SE Java Runtime Environment (JRE)" option there)

:ph34r: