Sun Java Web Start System Property Tags Remote Unauthorized Access Vulnerability
BID:12847
Info
Sun Java Web Start System Property Tags Remote Unauthorized Access Vulnerability
| Bugtraq ID: | 12847 |
| Class: | Design Error |
| CVE: |
CVE-2005-0418 CVE-2005-0836 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2005 12:00AM |
| Updated: | Mar 05 2007 08:55PM |
| Credit: | Jouko Pynnonen <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 Sun JRE (Solaris Production Release) 1.3.1 Sun JRE (Solaris Production Release) 1.3 _04 Sun JRE (Solaris Production Release) 1.3 _03 Sun JRE (Solaris Production Release) 1.3 _01 Sun JRE (Linux Production Release) 1.3.1 _04 Sun JRE (Linux Production Release) 1.3.1 _01a Sun Java Web Start 1.2 Sun Java 2 Runtime Environment 1.4.2 _06 Sun Java 2 Runtime Environment 1.4.2 _05 Sun Java 2 Runtime Environment 1.4.2 _04 Sun Java 2 Runtime Environment 1.4.2 _03 Sun Java 2 Runtime Environment 1.4.2 _02 Sun Java 2 Runtime Environment 1.4.2 _01 Sun Java 2 Runtime Environment 1.4.2 Sun Java 2 Runtime Environment 1.4.1 Sun Java 2 Runtime Environment 1.3.1 _08 Sun Java 2 Runtime Environment 1.3.1 _01 Sun Java 2 Runtime Environment 1.3 _05 Sun Java 2 Runtime Environment 1.3 _02 Sun Java 2 Runtime Environment 1.3 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Enterprise Server for S/390 9.0 Novell Linux Desktop 9 Gentoo Linux Apple Mac OS X Server 10.3.8 Apple Mac OS X Server 10.3.7 Apple Mac OS X Server 10.3.6 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 Apple Mac OS X Server 10.2.8 Apple Mac OS X Server 10.2.7 Apple Mac OS X Server 10.2.6 Apple Mac OS X Server 10.2.5 Apple Mac OS X Server 10.2.4 Apple Mac OS X Server 10.2.3 Apple Mac OS X Server 10.2.2 Apple Mac OS X Server 10.2.1 Apple Mac OS X Server 10.2 Apple Mac OS X Server 10.1.5 Apple Mac OS X Server 10.1.4 Apple Mac OS X Server 10.1.3 Apple Mac OS X Server 10.1.2 Apple Mac OS X Server 10.1.1 Apple Mac OS X Server 10.1 Apple Mac OS X Server 10.0 Apple Mac OS X 10.3.8 Apple Mac OS X 10.3.7 Apple Mac OS X 10.3.6 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 Apple Mac OS X 10.2.8 Apple Mac OS X 10.2.7 Apple Mac OS X 10.2.6 Apple Mac OS X 10.2.5 Apple Mac OS X 10.2.4 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 Apple Mac OS X 10.1.5 Apple Mac OS X 10.1.4 Apple Mac OS X 10.1.3 Apple Mac OS X 10.1.2 Apple Mac OS X 10.1.1 Apple Mac OS X 10.1 Apple Mac OS X 10.1 Apple Mac OS X 10.0.4 Apple Mac OS X 10.0.3 Apple Mac OS X 10.0.2 Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 3 Apple Mac OS X 10.0 |
| Not Vulnerable: |
Sun JRE (Linux Production Release) 1.4.2 _07 Sun Java Web Start 1.0.1 _02 Sun Java Web Start 1.0.1 _01 Sun Java Web Start 1.0.1 Sun Java Web Start 1.0 Sun Java 2 Runtime Environment 1.5 |
Discussion
Sun Java Web Start System Property Tags Remote Unauthorized Access Vulnerability
A remote unauthorized-access vulnerability affects Java Web Start because the application fails to properly validate user-supplied input before considering it trusted.
An attacker may leverage this issue to gain unauthorized read/write access to affected computers. Other attacks may also be possible. Note that unauthorized access granted in this way will be with the privileges of the unsuspecting user that visits a malicious website.
Reports from Harry Johnston indicate the OraClient 10g component of Oracle Database Server 10g incorporates a vulnerable version of the Java Runtime Environment and is therefore vulnerable to this issue.
A remote unauthorized-access vulnerability affects Java Web Start because the application fails to properly validate user-supplied input before considering it trusted.
An attacker may leverage this issue to gain unauthorized read/write access to affected computers. Other attacks may also be possible. Note that unauthorized access granted in this way will be with the privileges of the unsuspecting user that visits a malicious website.
Reports from Harry Johnston indicate the OraClient 10g component of Oracle Database Server 10g incorporates a vulnerable version of the Java Runtime Environment and is therefore vulnerable to this issue.
Exploit / POC
Sun Java Web Start System Property Tags Remote Unauthorized Access Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Sun Java Web Start System Property Tags Remote Unauthorized Access Vulnerability
Solution:
The vendor has released Sun Alert ID: 57740 along with upgrades dealing with this issue. Please see the referenced advisories for more information.
Sun Java 2 Runtime Environment 1.3 _05
Sun JRE (Solaris Production Release) 1.3 _03
Sun JRE (Solaris Production Release) 1.3 _04
Sun JRE (Solaris Production Release) 1.3 _01
Sun JRE (Solaris Production Release) 1.3.1
Sun Java 2 Runtime Environment 1.3.1 _08
Sun JRE (Linux Production Release) 1.3.1 _04
Sun JRE (Linux Production Release) 1.3.1 _01a
Sun Java 2 Runtime Environment 1.3.1 _01
Sun Java 2 Runtime Environment 1.4.1
Sun Java 2 Runtime Environment 1.4.2 _03
Sun Java 2 Runtime Environment 1.4.2
Sun Java 2 Runtime Environment 1.4.2 _02
Sun Java 2 Runtime Environment 1.4.2 _04
Apple Mac OS X Server 10.3.4
Apple Mac OS X 10.3.4
Apple Mac OS X Server 10.3.5
Apple Mac OS X 10.3.5
Apple Mac OS X Server 10.3.6
Apple Mac OS X 10.3.6
Apple Mac OS X Server 10.3.7
Apple Mac OS X 10.3.8
Apple Mac OS X Server 10.3.8
S.u.S.E. Linux Personal 9.0
S.u.S.E. Linux Professional 9.0
S.u.S.E. Linux Professional 9.0 x86_64
S.u.S.E. Linux Personal 9.0 x86_64
S.u.S.E. Linux Professional 9.1 x86_64
S.u.S.E. Linux Professional 9.1
S.u.S.E. Linux Personal 9.1 x86_64
S.u.S.E. Linux Professional 9.2 x86_64
S.u.S.E. Linux Personal 9.2 x86_64
Solution:
The vendor has released Sun Alert ID: 57740 along with upgrades dealing with this issue. Please see the referenced advisories for more information.
Sun Java 2 Runtime Environment 1.3 _05
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp -
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun JRE (Solaris Production Release) 1.3 _03
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp -
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun JRE (Solaris Production Release) 1.3 _04
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp -
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun JRE (Solaris Production Release) 1.3 _01
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp -
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun JRE (Solaris Production Release) 1.3.1
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp -
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun Java 2 Runtime Environment 1.3.1 _08
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp -
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun JRE (Linux Production Release) 1.3.1 _04
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp -
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun JRE (Linux Production Release) 1.3.1 _01a
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp -
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun Java 2 Runtime Environment 1.3.1 _01
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp -
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun Java 2 Runtime Environment 1.4.1
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp -
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun Java 2 Runtime Environment 1.4.2 _03
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp -
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun Java 2 Runtime Environment 1.4.2
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp -
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun Java 2 Runtime Environment 1.4.2 _02
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp -
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun Java 2 Runtime Environment 1.4.2 _04
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp -
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Apple Mac OS X Server 10.3.4
-
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X 10.3.4
-
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X Server 10.3.5
-
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X 10.3.5
-
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X Server 10.3.6
-
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X 10.3.6
-
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X Server 10.3.7
-
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X 10.3.8
-
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X Server 10.3.8
-
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
S.u.S.E. Linux Personal 9.0
-
SuSE java2-1.4.2-144.i586.rpm
SUSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/java2-1.4.2-144.i 586.rpm -
SuSE java2-jre-1.4.2-144.i586.rpm
SUSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/java2-jre-1.4.2-1 44.i586.rpm
S.u.S.E. Linux Professional 9.0
-
SuSE java2-1.4.2-144.i586.rpm
SUSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/java2-1.4.2-144.i 586.rpm -
SuSE java2-jre-1.4.2-144.i586.rpm
SUSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/java2-jre-1.4.2-1 44.i586.rpm
S.u.S.E. Linux Professional 9.0 x86_64
-
SuSE java2-1.4.2-144.x86_64.rpm
SUSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/java2-1.4.2-1 44.x86_64.rpm -
SuSE java2-jre-1.4.2-144.x86_64.rpm
SUSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/java2-jre-1.4 .2-144.x86_64.rpm
S.u.S.E. Linux Personal 9.0 x86_64
-
SuSE java2-1.4.2-144.x86_64.rpm
SUSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/java2-1.4.2-1 44.x86_64.rpm -
SuSE java2-jre-1.4.2-144.x86_64.rpm
SUSE Linux 9.0:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/java2-jre-1.4 .2-144.x86_64.rpm
S.u.S.E. Linux Professional 9.1 x86_64
-
SuSE java2-1.4.2-129.14.x86_64.rpm
SUSE Linux 9.1:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/java2-1.4.2-1 29.14.x86_64.rpm -
SuSE java2-jre-1.4.2-129.14.x86_64.rpm
SUSE Linux 9.1:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/java2-jre-1.4 .2-129.14.x86_64.rpm
S.u.S.E. Linux Professional 9.1
-
SuSE java2-1.4.2-129.14.i586.rpm
SUSE Linux 9.1:
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/java2-1.4.2-129.1 4.i586.rpm -
SuSE java2-jre-1.4.2-129.14.i586.rpm
SUSE Linux 9.1:
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/java2-jre-1.4.2-1 29.14.i586.rpm
S.u.S.E. Linux Personal 9.1 x86_64
-
SuSE java2-1.4.2-129.14.x86_64.rpm
SUSE Linux 9.1:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/java2-1.4.2-1 29.14.x86_64.rpm -
SuSE java2-jre-1.4.2-129.14.x86_64.rpm
SUSE Linux 9.1:
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/java2-jre-1.4 .2-129.14.x86_64.rpm
S.u.S.E. Linux Professional 9.2 x86_64
-
SuSE java-1_4_2-sun-1.4.2.08-0.1.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/java-1_4_2-sun- 1.4.2.08-0.1.x86_64.rpm -
SuSE java-1_4_2-sun-alsa-1.4.2.08-0.1.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/java-1_4_2-sun- alsa-1.4.2.08-0.1.x86_64.rpm -
SuSE java-1_4_2-sun-demo-1.4.2.08-0.1.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/java-1_4_2-sun- demo-1.4.2.08-0.1.x86_64.rpm -
SuSE java-1_4_2-sun-devel-1.4.2.08-0.1.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/java-1_4_2-sun- devel-1.4.2.08-0.1.x86_64.rpm -
SuSE java-1_4_2-sun-jdbc-1.4.2.08-0.1.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/java-1_4_2-sun- jdbc-1.4.2.08-0.1.x86_64.rpm -
SuSE java-1_4_2-sun-plugin-1.4.2.08-0.1.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/java-1_4_2-sun- plugin-1.4.2.08-0.1.x86_64.rpm -
SuSE java-1_4_2-sun-src-1.4.2.08-0.1.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/java-1_4_2-sun- src-1.4.2.08-0.1.x86_64.rpm
S.u.S.E. Linux Personal 9.2 x86_64
-
SuSE java-1_4_2-sun-1.4.2.08-0.1.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/java-1_4_2-sun- 1.4.2.08-0.1.x86_64.rpm -
SuSE java-1_4_2-sun-alsa-1.4.2.08-0.1.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/java-1_4_2-sun- alsa-1.4.2.08-0.1.x86_64.rpm -
SuSE java-1_4_2-sun-demo-1.4.2.08-0.1.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/java-1_4_2-sun- demo-1.4.2.08-0.1.x86_64.rpm -
SuSE java-1_4_2-sun-devel-1.4.2.08-0.1.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/java-1_4_2-sun- devel-1.4.2.08-0.1.x86_64.rpm -
SuSE java-1_4_2-sun-jdbc-1.4.2.08-0.1.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/java-1_4_2-sun- jdbc-1.4.2.08-0.1.x86_64.rpm -
SuSE java-1_4_2-sun-plugin-1.4.2.08-0.1.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/java-1_4_2-sun- plugin-1.4.2.08-0.1.x86_64.rpm -
SuSE java-1_4_2-sun-src-1.4.2.08-0.1.x86_64.rpm
SUSE Linux 9.2:
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/x86_64/java-1_4_2-sun- src-1.4.2.08-0.1.x86_64.rpm
References
Sun Java Web Start System Property Tags Remote Unauthorized Access Vulnerability
References:
References:
- CLSA-2005:977 - sun-jre (Conectiva)
- Sun Alert ID: 57740 - Security Vulnerability With Java Web Start (Sun)
- Java Web Start argument injection vulnerability (Jouko Pynnonen
)