Malicious Java applet security flaw in ClassLoader Vulnerability
BID:164
Info
Malicious Java applet security flaw in ClassLoader Vulnerability
| Bugtraq ID: | 164 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 1998 12:00AM |
| Updated: | Jul 14 1998 12:00AM |
| Credit: | This vulnerability was discovered by Princeton University's Safe Internet Programming Team. A post about it was sent to the Bugtraq mailing list on July 17, 1998 by Gary McGraw <[email protected]> |
| Vulnerable: |
Netscape Communicator 4.0 |
| Not Vulnerable: | |
Discussion
Malicious Java applet security flaw in ClassLoader Vulnerability
A vulnerability exists in the Java implementation included in Netscape Navigator/Communicator 4.0x that allows a malicious applet to disable all security controls. Once these controls have been deactivated, the applet can execute arbitrary code on the machine being attacked.
A vulnerability exists in the Java implementation included in Netscape Navigator/Communicator 4.0x that allows a malicious applet to disable all security controls. Once these controls have been deactivated, the applet can execute arbitrary code on the machine being attacked.
Exploit / POC
Malicious Java applet security flaw in ClassLoader Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Malicious Java applet security flaw in ClassLoader Vulnerability
Solution:
Netscape has issued patches against this vulnerability. These are available at ftp://ftp.netscape.com. A suitable temporary solution, should you believe yourself vulnerable, is to disable the execution of Java applets.
Solution:
Netscape has issued patches against this vulnerability. These are available at ftp://ftp.netscape.com. A suitable temporary solution, should you believe yourself vulnerable, is to disable the execution of Java applets.
References
Malicious Java applet security flaw in ClassLoader Vulnerability
References:
References: