Sun Java Web Start Unspecified Privilege Escalation Vulnerability
BID:13945
Info
Sun Java Web Start Unspecified Privilege Escalation Vulnerability
| Bugtraq ID: | 13945 |
| Class: | Unknown |
| CVE: |
CVE-2005-1973 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2005 12:00AM |
| Updated: | Sep 05 2006 11:23PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Sun SDK (Linux Production Release) 1.5 _01 Sun SDK (Linux Production Release) 1.5 Sun JRE (Linux Production Release) 1.5 _01 Sun Java 2 Runtime Environment 1.5 Sun Java 2 Runtime Environment 1.4.2 _03 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 8.1 Slackware Linux -current HP HP-UX B.11.23 HP HP-UX B.11.11 Gentoo Linux Blackdown Java 2 Standard Edition SDK 1.4.2 -01 Blackdown Java 2 Standard Edition SDK 1.4.2 Blackdown Java 2 Standard Edition SDK 1.4.1 Blackdown Java 2 Runtime Environment 1.4.2 -01 Blackdown Java 2 Runtime Environment 1.4.2 Blackdown Java 2 Runtime Environment 1.4.1 |
| Not Vulnerable: |
Sun SDK (Linux Production Release) 1.5 _03 Sun SDK (Linux Production Release) 1.5 _02 Sun JRE (Linux Production Release) 1.5 _05 Sun JRE (Linux Production Release) 1.5 _02 Blackdown Java 2 Standard Edition SDK 1.4.2 -02 Blackdown Java 2 Runtime Environment 1.4.2 -02 |
Discussion
Sun Java Web Start Unspecified Privilege Escalation Vulnerability
Sun Java Web Start is prone to an unspecified privilege-escalation vulnerability.
This vulnerability allows remote, untrusted Java applications to gain elevated privileges. This allows them to read or write local files, or to execute arbitrary local applications. These actions are normally forbidden for untrusted applications running in the Java virtual machine.
Further details are not available at this time. This BID will be updated as more information is disclosed.
Reports from Harry Johnston indicate that the OraClient 10g component of Oracle Database Server 10g incorporates a vulnerable version of the Java Runtime Environment and is therefore vulnerable to this issue.
Sun Java Web Start is prone to an unspecified privilege-escalation vulnerability.
This vulnerability allows remote, untrusted Java applications to gain elevated privileges. This allows them to read or write local files, or to execute arbitrary local applications. These actions are normally forbidden for untrusted applications running in the Java virtual machine.
Further details are not available at this time. This BID will be updated as more information is disclosed.
Reports from Harry Johnston indicate that the OraClient 10g component of Oracle Database Server 10g incorporates a vulnerable version of the Java Runtime Environment and is therefore vulnerable to this issue.
Exploit / POC
Sun Java Web Start Unspecified Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Sun Java Web Start Unspecified Privilege Escalation Vulnerability
Solution:
The vendor has released upgraded versions of the affected software as well as Sun Alert ID 101748 to address this issue. Please see the referenced alert for more information.
Further analysis has revealed that Gentoo advisory GLSA 200506-14 does not apply to this BID. The advisory is being removed.
Slackware has released advisory SSA:2005-170-01 to address this issue. Please see the referenced advisory for more information.
HP has released advisory HPSBUX01214 (SSRT051003 rev.0 - HP-UX Java Web Start remote unauthorized privileged access) to address this issue in HP-UX B.11.11 and HP-UX B.11.23. Please see the referenced advisory for more information.
Sun Java 2 Runtime Environment 1.4.2 _03
Sun Java 2 Runtime Environment 1.5
Sun SDK (Linux Production Release) 1.5 _01
Sun JRE (Linux Production Release) 1.5 _01
Sun SDK (Linux Production Release) 1.5
Solution:
The vendor has released upgraded versions of the affected software as well as Sun Alert ID 101748 to address this issue. Please see the referenced alert for more information.
Further analysis has revealed that Gentoo advisory GLSA 200506-14 does not apply to this BID. The advisory is being removed.
Slackware has released advisory SSA:2005-170-01 to address this issue. Please see the referenced advisory for more information.
HP has released advisory HPSBUX01214 (SSRT051003 rev.0 - HP-UX Java Web Start remote unauthorized privileged access) to address this issue in HP-UX B.11.11 and HP-UX B.11.23. Please see the referenced advisory for more information.
Sun Java 2 Runtime Environment 1.4.2 _03
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun Java 2 Runtime Environment 1.5
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun SDK (Linux Production Release) 1.5 _01
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun JRE (Linux Production Release) 1.5 _01
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun SDK (Linux Production Release) 1.5
-
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
References
Sun Java Web Start Unspecified Privilege Escalation Vulnerability
References:
References:
- J2SE Product Page (Sun)
- Java Homepage (Sun)
- Sun Alert ID: 101748 (Sun)