This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

CERT's warn old java bug being exploited (NOW)

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1039
Last Updated: 2006-01-13 20:17:17 UTC
"US-CERT* and AUSCERT** warn about a bug in java being exploited. They claim (the) bug was made public in November 2005.
…Download that latest greatest java environment now if you haven't done so already and upgrade. Better yet: in addition to upgrading all java versions, also check those browser settings and turn java off for all sites that you either not trust 100% to execute code on your machines or that don't absolutely need it to work.
UPDATE
We have been informed multiple times the hostile java seems to be at a webserver at fullchain [dot] net. Might be interesting to check your logs in a corporate environment. The supposedly hostile code is still there so we won't be providing detailed URLs for now. The class file on that website is not detected as malicious by any anti-virus product participating in virustotal… It's also necessary to remove the old java environments, not just get the new ones as an attacker can target the old environments when they are still present.
* http://www.us-cert.gov/current/current_activity.html#javaapi
** http://www.auscert.org.au/render.html?it=5925

>>> http://sunsolve.sun.com/searchproxy/docume…y=1-26-102003-1
"…Resolution…
* SDK and JRE 1.4.2_09 and later
* JDK and JRE 5.0 Update 4 and later
J2SE 1.4.2 is available for download at http://java.sun.com/j2se/1.4.2/download.html
J2SE 5.0 is available for download at http://java.sun.com/j2se/1.5.0/download.jsp …
Note: It is recommended that affected versions be removed from your system…"

:ph34r:
FYI…

- http://secunia.com/advisories/18760/
Release Date: 2006-02-08
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch…
The following releases are affected by one or more of the seven vulnerabilities on Windows, Solaris, and Linux platforms:
* JDK and JRE 5.0 Update 5 and prior
* SDK and JRE 1.4.2_09 and prior
* SDK and JRE 1.3.1_16 and prior
Solution:
Update to the fixed versions.
- JDK and JRE 5.0:
Update to JDK and JRE 5.0 Update 6 or later.
http://java.sun.com/j2se/1.5.0/download.jsp
- SDK and JRE 1.4.x:
Update to SDK and JRE 1.4.2_10 or later.
http://java.sun.com/j2se/1.4.2/download.html
- SDK and JRE 1.3.x:
Update to SDK and JRE 1.3.1_17 or later.
http://java.sun.com/j2se/1.3/download.html …"

:ph34r: