Sun Microsystems, Inc. Java Plug-in and Java Web Start contain a flaw that may allow a malicious user to bypass certain security restrictions. The issue is triggered when vulnerable versions of the Java Plugin and Java Web Start are installed, and a specially crafted applet specifies the vulnerable versions in which to run. It is possible that the flaw may allow applets or applications to run with a specified version of the JRE that does not have the latest security fixes resulting in a loss of integrity.
Classification
Location:
Remote / Network Access
Attack Type:
Misconfiguration
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Technical
Java Plug-in included with J2SE 5.0 Update 5 and earlier, 1.4.x, 1.3.1 and 1.3.0_02 and later are affected.
Java Web Start included with J2SE 5.0 Update 5 and earlier, and 1.4.2 are affected.
Solution
Upgrade to Java Plug-in 5.0 Update 6 or higher for Windows and Java Web Start 5.0 Update 6 and higher for Windows, Solaris, and Linux as it has been reported to fix this vulnerability.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.