Sun SDK and JRE applet bypass sandbox restrictions

sdk-jre-applet-restriction-bypass (18188) The risk level is classified as HighHigh Risk

Description:

Sun Microsystems Java Runtime Environment (JRE) and Software Development Kit (SDK) could allow a remote attacker to use a malicious Java applet to bypass sandbox restrictions, caused by a vulnerability in the Sun's Java Plug-in technology. If the victim is running a browser on a Java Virtual Machine (VM), a remote attacker could create a malicious Java applet to bypass restrictions and execute arbitrary code with user privileges.

Platforms Affected:

  • Gentoo, Linux
  • Microsoft, Windows 2000 Advanced Server
  • Microsoft, Windows 2003 Server
  • Microsoft, Windows XP SP2 Professional
  • RedHat, Enterprise Linux 2.1 AS
  • RedHat, Enterprise Linux 2.1 ES
  • RedHat, Enterprise Linux 2.1 WS
  • RedHat, Enterprise Linux 3 WS
  • RedHat, Enterprise Linux 3 AS
  • RedHat, Enterprise Linux 3 ES
  • Sun, JRE 1.3.1_12 and prior
  • Sun, JRE 1.4.0
  • Sun, JRE 1.4.1
  • Sun, JRE 1.4.2_05 and prior
  • Sun, SDK 1.3.1_12 and prior
  • Sun, SDK 1.4.0
  • Sun, SDK 1.4.1
  • Sun, SDK 1.4.2_05 and prior
  • Sun, Solaris 7.0
  • Sun, Solaris 8
  • Sun, Solaris 9
  • SuSE, SuSE Linux 8.0
  • SuSE, SuSE Linux 8.2
  • SuSE, SuSE Linux 9.0
  • SuSE, SuSE Linux Desktop 8.0
  • SuSE, SuSE Linux Enterprise Server 8.0
  • SuSE, SuSE SLES 9

Remedy:

Upgrade to the latest version of Sun JRE/SDK (1.4.2_06 or 1.3.1_13 or later), available from the Sun Microsystems, Inc. Web site. See References.

For Gentoo Linux:
Upgrade to the latest version of Java, as listed in GLSA 200411-38. See References.

For Conectiva Linux:
Upgrade to the latest sun-jre package, as listed below. Refer to Conectiva Linux Security Announcement CLSA-2004:900 for more information. See References.

Conectiva Linux 10.0: 1.4.2_06-56946U10_1cl or later

For other distributions:
Contact your vendor for upgrade or patch information.

Consequences:

Gain Access

References:

Reported:

Nov 22, 2004

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.

For corrections or additions please email xforce@iss.net

Return to the main page