Sun JDK/JRE Disallowed Class Loading Vulnerability
BID:2051
Info
Sun JDK/JRE Disallowed Class Loading Vulnerability
| Bugtraq ID: | 2051 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2000 12:00AM |
| Updated: | Nov 29 2000 12:00AM |
| Credit: | Reported by Sun Microsystems in an advisory dated November 29, 2000. |
| Vulnerable: |
Sun JDK (Windows Production Release) 1.2.2 _004 Sun JDK (Windows Production Release) 1.2.1 _003 Sun JDK (Windows Production Release) 1.1.8 _002 Sun JDK (Windows Production Release) 1.1.7 B_005 Sun JDK (Windows Production Release) 1.1.6 _007 Sun JDK (Solaris Reference Release) 1.2.2 _004 Sun JDK (Solaris Reference Release) 1.2.1 _003 Sun JDK (Solaris Reference Release) 1.1.8 _002 Sun JDK (Solaris Reference Release) 1.1.7 B_005 Sun JDK (Solaris Reference Release) 1.1.6 _007 Sun JDK (Solaris Production Release) 1.2.2 _05 Sun JDK (Solaris Production Release) 1.2.1 Sun JDK (Solaris Production Release) 1.1.8 _10 Sun JDK (Solaris Production Release) 1.1.7 B Sun JDK (Solaris Production Release) 1.1.6 Sun JDK (Linux Production Release) 1.2.2 _05 Sun Java HotSpot Performance Engine 1.0.1 Sun Java HotSpot Performance Engine 1.0 HP MPE/iX 7.0 HP MPE/iX 6.5 HP MPE/iX 6.0 |
| Not Vulnerable: |
Sun SDK (Linux Production Release) 1.3 Sun JDK (Solaris Reference Release) 1.2.2 _006 Sun JDK (Solaris Reference Release) 1.2.1 _004 Sun JDK (Solaris Reference Release) 1.1.8 _005 Sun JDK (Solaris Reference Release) 1.1.7 B_007 Sun JDK (Solaris Reference Release) 1.1.6 _009 Sun JDK (Solaris Production Release) 1.2.2 _06 Sun JDK (Linux Production Release) 1.2.2 _06 Sun Java HotSpot Performance Engine 2.0 |
Discussion
Sun JDK/JRE Disallowed Class Loading Vulnerability
A vulnerability exists in certain versions of Sun's Java Runtime Environment, and potentially in JREs from other vendors having been derived from Sun's Java Development Kit source tree.
Untrusted Java code may be able to calls to classes which would normally not be permitted. As a result, a malicious applet could potentially be used, for example, to compromise the security of a host system visiting an attacker's web site.
The original Sun Microsystems advisory does not provide further specific details of this vulnerability.
A vulnerability exists in certain versions of Sun's Java Runtime Environment, and potentially in JREs from other vendors having been derived from Sun's Java Development Kit source tree.
Untrusted Java code may be able to calls to classes which would normally not be permitted. As a result, a malicious applet could potentially be used, for example, to compromise the security of a host system visiting an attacker's web site.
The original Sun Microsystems advisory does not provide further specific details of this vulnerability.
Exploit / POC
Sun JDK/JRE Disallowed Class Loading Vulnerability
Currently SecurityFocus staff are unaware of any exploits for this vulnerability.
Currently SecurityFocus staff are unaware of any exploits for this vulnerability.
Solution / Fix
Sun JDK/JRE Disallowed Class Loading Vulnerability
Solution:
Sun recommends that upgrading to the latest JDK/JRE releases.
Sun JDK (Windows Production Release) 1.1.6 _007
Sun JDK (Solaris Reference Release) 1.1.6 _007
Sun JDK (Windows Production Release) 1.1.7 B_005
Sun JDK (Solaris Reference Release) 1.1.7 B_005
Sun JDK (Solaris Production Release) 1.1.8 _10
Sun JDK (Windows Production Release) 1.1.8 _002
Sun JDK (Solaris Reference Release) 1.1.8 _002
Sun JDK (Solaris Reference Release) 1.2.1 _003
Sun JDK (Windows Production Release) 1.2.1 _003
Sun JDK (Solaris Reference Release) 1.2.2 _004
Sun JDK (Solaris Production Release) 1.2.2 _05
Sun JDK (Linux Production Release) 1.2.2 _05
HP MPE/iX 6.0
HP MPE/iX 6.5
HP MPE/iX 7.0
Solution:
Sun recommends that upgrading to the latest JDK/JRE releases.
Sun JDK (Windows Production Release) 1.1.6 _007
-
Sun JDK 1.1.6_009 Win32
http://java.sun.com/products/jdk/1.1.6/download-jdk-windows.html
Sun JDK (Solaris Reference Release) 1.1.6 _007
-
Sun JDK 1.1.6_009 Solaris Reference
http://java.sun.com/products/jdk/1.1.6/download-jdk-solaris.html
Sun JDK (Windows Production Release) 1.1.7 B_005
-
Sun JDK 1.1.7B_007 Win32
http://java.sun.com/products/jdk/1.1.7B/download-jdk-windows.html
Sun JDK (Solaris Reference Release) 1.1.7 B_005
-
Sun JDK 1.1.7B_007 Solaris Reference
http://java.sun.com/products/jdk/1.1.7B/download-jdk-solaris.html
Sun JDK (Solaris Production Release) 1.1.8 _10
-
Sun JDK 1.1.8_12 Solaris Production
http://www.sun.com/software/solaris/java/archive.html
Sun JDK (Windows Production Release) 1.1.8 _002
-
Sun JDK 1.1.x Win32
http://java.sun.com/products/jdk/1.1/download-jdk-windows.html
Sun JDK (Solaris Reference Release) 1.1.8 _002
-
Sun JDK 1.1.8_005 Solaris Reference
http://java.sun.com/products/jdk/1.1/download-jdk-solaris.html
Sun JDK (Solaris Reference Release) 1.2.1 _003
-
Sun SDK v1.2.1_004 Solaris Reference
http://java.sun.com/products/jdk/1.2.1/download-solaris.html
Sun JDK (Windows Production Release) 1.2.1 _003
-
Sun SDK v 1.2.1_004 Windows 95 / 98 / NT 4.0
http://java.sun.com/products/jdk/1.2.1/download-windows.html
Sun JDK (Solaris Reference Release) 1.2.2 _004
-
Sun SDK 1.3.0 Solaris
http://www.sun.com/software/solaris/java/download.html
Sun JDK (Solaris Production Release) 1.2.2 _05
-
Sun SDK 1.3.0 Solaris
http://www.sun.com/software/solaris/java/download.html
Sun JDK (Linux Production Release) 1.2.2 _05
-
Sun JDK 1.2.2_006 Linux Production
http://java.sun.com/products/jdk/1.2/download-linux.html
HP MPE/iX 6.0
HP MPE/iX 6.5
HP MPE/iX 7.0
References
Sun JDK/JRE Disallowed Class Loading Vulnerability
References:
References: