Arbitrary Code Execution in Sun Java 2 Platform, Standard Edition (J2SE) 1.4.2_01 and 1.4.2_04

A vulnerability exists in Sun Java 2 Platform, Standard Edition (J2SE) 1.4.2_01 and 1.4.2_04 that could result in the remote execution of arbitrary code on the vulnerable system.

Ken Pfeil

November 30, 2004

1 Min Read
ITPro Today logo

Reported November 23, 2004, byiDEFENSE

VERSIONS AFFECTED

·         Java 2 Platform, Standard Edition (J2SE) 1.4.2_01 and 1.4.2_04 from Sun Microsystems

DESCRIPTION
A vulnerability exists in Sun Java 2 Platform, Standard Edition (J2SE) 1.4.2_01 and 1.4.2_04 that could result in the remote executionof arbitrary code on the vulnerable system. The problem exists within theaccess controls of the Java to JavaScript data exchange in Web browsers usingSun's Java Plug-in technology. This vulnerability lets JavaScript code load anunsafe class, which isn't normally possible from a Java applet.

VENDOR RESPONSE
Sun Microsystems has released J2SE 1.4.2_06 toaddress this vulnerability.

CREDIT
Discovered by iDEFENSE.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like