Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[ GLSA 200411-38 ] Sun and Blackdown Java: Applet privilege escalation
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index News & Announcements
View previous topic :: View next topic  
Author Message
GLSA
Moderator
Moderator


Joined: 13 Jun 2003
Posts: 4078
Location: Barcelona, Spain

PostPosted: Mon Nov 29, 2004 10:04 pm    Post subject: [ GLSA 200411-38 ] Sun and Blackdown Java: Applet privilege Reply with quote

Gentoo Linux Security Advisory

Title: Sun and Blackdown Java: Applet privilege escalation (GLSA 200411-38)
Severity: normal
Exploitable: remote
Date: November 29, 2004
Updated: May 31, 2006
Bug(s): #72172, #72221
ID: 200411-38

Synopsis

The Java plug-in security in Sun and Blackdown Java environments can be bypassed to access arbitrary packages, allowing untrusted Java applets to perform unrestricted actions on the host system.

Background

Sun and Blackdown both provide implementations of Java Development Kits (JDK) and Java Runtime Environments (JRE). All these implementations provide a Java plug-in that can be used to execute Java applets in a restricted environment for web browsers.

Affected Packages

Package: dev-java/sun-jdk
Vulnerable: < 1.4.2.06
Unaffected: >= 1.4.2.06
Architectures: x86 amd64

Package: dev-java/sun-jre-bin
Vulnerable: < 1.4.2.06
Unaffected: >= 1.4.2.06
Architectures: x86 amd64

Package: dev-java/blackdown-jdk
Vulnerable: < 1.4.2.01
Unaffected: >= 1.4.2.01
Architectures: x86 amd64

Package: dev-java/blackdown-jre
Vulnerable: < 1.4.2.01
Unaffected: >= 1.4.2.01
Architectures: x86 amd64


Description

All Java plug-ins are subject to a vulnerability allowing unrestricted Java package access.

Impact

A remote attacker could embed a malicious Java applet in a web page and entice a victim to view it. This applet can then bypass security restrictions and execute any command or access any file with the rights of the user running the web browser.

Workaround

As a workaround you could disable Java applets on your web browser.

Resolution

All Sun JDK users should upgrade to the latest version:
Code:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-java/sun-jdk-1.4.2.06"
All Sun JRE users should upgrade to the latest version:
Code:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-java/sun-jre-bin-1.4.2.06"
All Blackdown JDK users should upgrade to the latest version:
Code:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-java/blackdown-jdk-1.4.2.01"
All Blackdown JRE users should upgrade to the latest version:
Code:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-java/blackdown-jre-1.4.2.01"
Note: You should unmerge all vulnerable versions to be fully protected.

References

iDEFENSE Security Advisory 11.22.04
CAN-2004-1029
Blackdown Security Advisory 2004-01


Last edited by GLSA on Sun Nov 05, 2006 4:17 am; edited 4 times in total
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index News & Announcements All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum