FYI…

- http://secunia.com/advisories/25823/
Release Date: 2007-06-29
Critical: Highly critical
Impact: Security Bypass, Manipulation of data
Where: From remote
Solution Status: Vendor Patch
Software:
Java Web Start 1.x
Sun Java JDK 1.5.x
Sun Java JRE 1.4.x
Sun Java JRE 1.5.x / 5.x
Sun Java SDK 1.4.x
…The vulnerability affects Java Web Start in JDK and JRE 5.0 Update 11 and earlier and Java Web Start in SDK and JRE 1.4.2_13 and earlier for the Windows platform…
Solution: Apply updates.
Java Web Start in JDK and JRE 5.0 Update 12 or later
http://java.sun.com/j2se/1.5.0/download.jsp
Java Web Start in SDK and JRE 1.4.2_14 or later
http://java.sun.com/j2se/1.4.2/download.html …
Original Advisory:
http://sunsolve.sun.com/search/document.do…y=1-26-102957-1 …"

Also see: http://secunia.com/advisories/25769/
( http://sunsolve.sun.com/search/document.do…y=1-26-102958-1 )

:ph34r: