CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image Sun Security Bulletin : Java Plug-in and Java Web Start image
Security Hole
mowgreen writes "http://sunsolve.sun.com/search/document.do?assetkey=1-26-102557-1
Sun Alert ID: 102557 (RESOLVED) Synopsis: Java Plug-in and Java Web Start May Allow Applets and Applications to Run With Unpatched JRE Product: Java 2 Platform, Standard Edition Category: Security
  • 1. Impact
    The Java Plug-in and Java Web Start both allow applets and applications to specify the version of the Java Runtime Environment (JRE) to run with. However, the versions of Java Web Start and the Java Plug-in listed in Section 2 below may allow applets or applications to run with a specified version of the JRE that does not have the latest security fixes.


  • 2. Contributing Factors
    This issue can occur in the following releases (for Solaris, Lunix and Windows platforms):
    * Java Plug-in included with J2SE 5.0 Update 5 and earlier, 1.4.x, 1.3.1, and 1.3.0_02 and later
    * Java Web Start included with J2SE 5.0 Update 5 and earlier, and 1.4.2
    * Java Web Start 1.2, 1.0.2, 1.0.1, and 1.0

  • To determine the default version of the JRE on a system for Solaris and Lunix, the following command can be run:

    % java -version
    Note: The above command only determines the default version. Other versions may also be installed on the system. To determine the default version of the JRE on a system for Windows:
    1. Click Start
    2. Select Run
    3. Type cmd (starts a command-line)
    4. At the prompt, type java -version
    5. Press Enter

    Note: The above command only determines the default version. Other versions may also be installed on the system.

    1. Prior to 5.0 Update 6, an applet could specify the version of the JRE on which it would run. With 5.0 Update 6 and later installed on the Windows platform, all applets are executed with the latest version of the JRE.
    I have been blogging about this issue and pestering Sun since February 2005. http://mowgreen.castlecops.com

    The Security Bulleting states
    Note: It is recommended that affected versions be removed from your system. For more information, see the installation notes on the respective java.sun.com download pages.
    Nowhere on java.sun.com is there a readily accessible explanation of just why the older, vulnerable versions must be uninstalled. One must manually uninstall all versions prior to 1.5.0_06 from Add/Remove Programs in the Control Panel in order to mitigate this vulnerability.
    Why is it that the Java Update mechanism ( jusched.exe ) does NOT remove the older, vulnerable versions ? "
    Posted on Friday, 01 September 2006 @ 20:23:42 UTC by Paul (1698 reads)
    [ Trackback ]
    image

    "Sun Security Bulletin : Java Plug-in and Java Web Start" | Login/Create an Account | 2 comments | Search
    Threshold
    The comments are owned by the poster. We aren't responsible for their content.

    No Comments Allowed for Anonymous, please register

    Re: Sun Security Bulletin : Java Plug-in and Java Web Start (Score: 1)
    by Ikeb  on Saturday, 02 September 2006 @ 18:55:00 UTC
    (User Info | Send a Message)
    Thanks for this Mowgreen. Though I only very recently upgraded to Windows Server 2003 and though I was up to date with J2SE Runtime Environment 5.0 Update 6, thanks to this news item, I discovered that Update 1 was also installed.

    I suspect that many folks are unaware of this vulnerability, fully expecting that if they installed the latest Java plugin, they are protected against known vulnerabilities. Furthermore, I expect that a large number of folks unwittingly have Java vulnerabilities due to this flaw in Sun's update mechanism.



    Re: Sun Security Bulletin : Java Plug-in and Java Web Start (Score: 1)
    by blacklupine  on Sunday, 03 September 2006 @ 09:24:34 UTC
    (User Info | Send a Message)
    Thanks mowgreen for this article and the work you have done to highlight this problem.

    Having checked my system I found that whilst I was up todate with J2SE Runtime Environment 1.5.0_6 installed I still had Updates 1 and 4 on my computer.

    Much appreciated



     
    Login
    spacer
    Nickname

    Password

    Security Code: Type Security Code: Usage signifies AUP acceptance
    · New User? · Click here to create a registered account.
    block bottom
    Related Links
    spacer
    · del.icio.us!
    · digg it!
    · reddit!
    · TrackBack (0)
    · Microsoft
    · HotScripts
    · Apple
    · Linux Manuals
    · W3 Consortium
    · More about Security Hole
    · News by Paul


    Most read story about Security Hole:
    Windows Media Player, Spyware and Trojan

    block bottom
    Article Rating
    spacer
    Average Score: 4
    Votes: 3


    Please take a second and vote for this article:

    Bad
    Regular
    Good
    Very Good
    Excellent


    block bottom
    Options
    spacer

    Printer Friendly Page  Printer Friendly Page

    block bottom
    spacer spacer