Java Runtime Environment Font Parsing Bug Lets Remote Applets Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1018576
|
|
SecurityTracker URL: http://securitytracker.com/id?1018576
|
|
CVE Reference: CVE-2007-4381
(Links to External Site)
|
Updated: Oct 16 2007
|
Original Entry Date: Aug 16 2007
|
Impact: Disclosure of system information, Disclosure of user information, Execution of arbitrary code via network, Modification of user information, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Sun Alert
|
Version(s): 5.0 Update 9 and prior versions
|
Description: A vulnerability was reported in Java Runtime Environment (JRE). A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create a specially crafted Java applet that, when loaded by the target user, will trigger an error in the font
parsing code and run with elevated privileges. The applet can read and write files on the target user's system or execute applications
on the target user's system with the privileges of the target user.
John Heasman of NGSSoftware reported this vulnerability.
|
Impact: A remote user can create Java that, when loaded by the target user, will read or write files and execute code on the target user's system.
|
Solution: The vendor has issued the following fixes.
This issue is addressed in the following releases (for Solaris, Linux, and Windows):
* JDK and JRE 5.0 Update 10 or later
* SDK and JRE 1.4.2_15 or later
J2SE 5.0 is available for download at the following
link:
* http://java.sun.com/j2se/1.5.0/download.jsp
The latest J2SE 5.0 Update Release for Solaris is also available in
the following patches:
* J2SE 5.0: update 12 (as delivered in patch 118666-12)
* J2SE 5.0: update 12 (as delivered in
patch 118667-12 (64bit))
* J2SE 5.0_x86: update 12 (as delivered in patch 118668-12)
* J2SE 5.0_x86: update 12 (as delivered
in patch 118669-12 (64bit))
J2SE 1.4.2 is available for download at:
* http://java.sun.com/j2se/1.4.2/download.html
The
Sun advisory is available at:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103024-1
|
Vendor URL: sunsolve.sun.com/search/document.do?assetkey=1-26-103024-1 (Links to External Site)
|
Cause: Not specified
|
Underlying OS: Linux (Any), UNIX (Solaris - SunOS), Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Wed, 15 Aug 2007 23:48:13 -0400
Subject: Vulnerability in the Java Runtime Environment Font Parsing Code may Allow an Untrusted Applet to Elevate Privileges
|
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103024-1
|
|