|
|
|
Vulnerability Note VU#336105Sun Java JRE vulnerable to unauthorized network accessOverviewThe Sun Java Runtime Environment (JRE) contains a vulnerability that may allow unintended access to network resources.I. DescriptionThe Sun Java Runtime Environment (JRE) allows users to run Java applications in a browser or as standalone programs. Sun has made the JRE available for multiple operating systems.Per Sunsolve Document ID 103079:
The following java products are affected by this vulnerability: JDK and JRE 6 Update 2 and earlier JDK and JRE 5.0 Update 12 and earlier SDK and JRE 1.4.2_15 and earlier SDK and JRE 1.3.1_20 and earlier II. ImpactAn attacker may be able to run a Java applet on a vulnerable system to gain access to network connections to resources not otherwise accessible and expose vulnerabilitites within those network resources.III. SolutionUpgradeSun has released an upgrade to address this issue. See Sunsolve Document ID 103079 for more details. To adjust the JRE update settings, see the update section of the Java deployment guide. Disable Java
Referenceshttp://www.cert.org/archive/html/securing_browser.html This vulnerability was reported in Sun Alert 103079. Sun credits Billy Rios of VeriSign with providing information about this issue. This document was written by Joseph Pruszynski.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||