Arbitrary Code Execution in Sun Java 2 Platform, Standard Edition (J2SE) 1.4.2_01 and 1.4.2_04
A vulnerability exists in Sun Java 2 Platform, Standard Edition (J2SE) 1.4.2_01 and 1.4.2_04 that could result in the remote execution of arbitrary code on the vulnerable system.
November 30, 2004
Reported November 23, 2004, byiDEFENSE
VERSIONS AFFECTED
· Java 2 Platform, Standard Edition (J2SE) 1.4.2_01 and 1.4.2_04 from Sun Microsystems |
DESCRIPTION
A vulnerability exists in Sun Java 2 Platform, Standard Edition (J2SE) 1.4.2_01 and 1.4.2_04 that could result in the remote executionof arbitrary code on the vulnerable system. The problem exists within theaccess controls of the Java to JavaScript data exchange in Web browsers usingSun's Java Plug-in technology. This vulnerability lets JavaScript code load anunsafe class, which isn't normally possible from a Java applet.
VENDOR RESPONSE
Sun Microsystems has released J2SE 1.4.2_06 toaddress this vulnerability.
CREDIT
Discovered by iDEFENSE.
About the Author
You May Also Like