Sun Java Web Start Unauthorized Access Vulnerability
BID:23728
Info
Sun Java Web Start Unauthorized Access Vulnerability
| Bugtraq ID: | 23728 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-2435 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 29 2007 12:00AM |
| Updated: | Apr 29 2009 11:36PM |
| Credit: | Fujitsu security team discovered this issue. |
| Vulnerable: |
Sun SDK (Windows Production Release) 1.4.2 _10 Sun SDK (Windows Production Release) 1.4.2 _09 Sun SDK (Windows Production Release) 1.4.2 _08 Sun SDK (Windows Production Release) 1.4.2 _05 Sun SDK (Windows Production Release) 1.4.2 _04 Sun SDK (Windows Production Release) 1.4.2 _03 Sun SDK (Windows Production Release) 1.4.2 Sun SDK (Windows Production Release) 1.4.2_13 Sun SDK (Windows Production Release) 1.4.2_12 Sun SDK (Windows Production Release) 1.4.2_11 Sun SDK (Solaris Production Release) 1.4.2 _10 Sun SDK (Solaris Production Release) 1.4.2 _09 Sun SDK (Solaris Production Release) 1.4.2 _08 Sun SDK (Solaris Production Release) 1.4.2 _05 Sun SDK (Solaris Production Release) 1.4.2 _04 Sun SDK (Solaris Production Release) 1.4.2 _03 Sun SDK (Solaris Production Release) 1.4.2 Sun SDK (Solaris Production Release) 1.4.2_13 Sun SDK (Solaris Production Release) 1.4.2_12 Sun SDK (Solaris Production Release) 1.4.2_11 Sun SDK (Linux Production Release) 1.4.2 _10 Sun SDK (Linux Production Release) 1.4.2 _09 Sun SDK (Linux Production Release) 1.4.2 _08 Sun SDK (Linux Production Release) 1.4.2 _05 Sun SDK (Linux Production Release) 1.4.2 _04 Sun SDK (Linux Production Release) 1.4.2 _03 Sun SDK (Linux Production Release) 1.4.2 _02 Sun SDK (Linux Production Release) 1.4.2 _01 Sun SDK (Linux Production Release) 1.4.2 Sun SDK (Linux Production Release) 1.4.2_13 Sun SDK (Linux Production Release) 1.4.2_12 Sun SDK (Linux Production Release) 1.4.2_11 Sun JRE (Windows Production Release) 1.4.2 _10 Sun JRE (Windows Production Release) 1.4.2 _09 Sun JRE (Windows Production Release) 1.4.2 _08 Sun JRE (Windows Production Release) 1.4.2 _07 Sun JRE (Windows Production Release) 1.4.2 _06 Sun JRE (Windows Production Release) 1.4.2 _05 Sun JRE (Windows Production Release) 1.4.2 _04 Sun JRE (Windows Production Release) 1.4.2 _03 Sun JRE (Windows Production Release) 1.4.2 _02 Sun JRE (Windows Production Release) 1.4.2 _01 Sun JRE (Windows Production Release) 1.4.2 Sun JRE (Windows Production Release) 1.4.2_13 Sun JRE (Windows Production Release) 1.4.2_12 Sun JRE (Windows Production Release) 1.4.2_11 Sun JRE (Solaris Production Release) 1.4.2 _10 Sun JRE (Solaris Production Release) 1.4.2 _09 Sun JRE (Solaris Production Release) 1.4.2 _08 Sun JRE (Solaris Production Release) 1.4.2 _07 Sun JRE (Solaris Production Release) 1.4.2 _06 Sun JRE (Solaris Production Release) 1.4.2 _05 Sun JRE (Solaris Production Release) 1.4.2 _04 Sun JRE (Solaris Production Release) 1.4.2 _03 Sun JRE (Solaris Production Release) 1.4.2 _02 Sun JRE (Solaris Production Release) 1.4.2 _01 Sun JRE (Solaris Production Release) 1.4.2 Sun JRE (Solaris Production Release) 1.4.2_13 Sun JRE (Solaris Production Release) 1.4.2_12 Sun JRE (Solaris Production Release) 1.4.2_11 Sun JRE (Linux Production Release) 1.4.2 _10 Sun JRE (Linux Production Release) 1.4.2 _09 Sun JRE (Linux Production Release) 1.4.2 _08 Sun JRE (Linux Production Release) 1.4.2 _07 Sun JRE (Linux Production Release) 1.4.2 _06 Sun JRE (Linux Production Release) 1.4.2 _05 Sun JRE (Linux Production Release) 1.4.2 _04 Sun JRE (Linux Production Release) 1.4.2 _03 Sun JRE (Linux Production Release) 1.4.2 _02 Sun JRE (Linux Production Release) 1.4.2 _01 Sun JRE (Linux Production Release) 1.4.2 Sun JRE (Linux Production Release) 1.4.2_13 Sun JRE (Linux Production Release) 1.4.2_12 Sun JRE (Linux Production Release) 1.4.2_11 Sun Java 2 Runtime Environment 5.0.Update 9 Sun Java 2 Runtime Environment 5.0.Update 10 Sun Java 2 Runtime Environment 5.0 Update 8 Sun Java 2 Runtime Environment 5.0 Update 7 Sun Java 2 Runtime Environment 5.0 Update 6 Sun Java 2 Runtime Environment 5.0 Update 5 Sun Java 2 Runtime Environment 5.0 Update 4 Sun Java 2 Runtime Environment 5.0 Update 3 Sun Java 2 Runtime Environment 5.0 Update 2 Sun Java 2 Runtime Environment 5.0 Update 1 Sun Java 2 Runtime Environment 5.0 Redhat Red Hat Network Satellite Server 5.0 Redhat Network Satellite (for RHEL 4) 4.2 Redhat Network Satellite (for RHEL 3) 4.2 Redhat Enterprise Linux Supplementary 5 server Redhat Enterprise Linux Extras 4 Redhat Enterprise Linux Extras 3 Redhat Enterprise Linux Desktop Supplementary 5 client Gentoo Linux Gentoo dev-java/ibm-jre-bin 1.5.0.6 Gentoo dev-java/ibm-jre-bin 1.4.2.10 Gentoo dev-java/ibm-jdk-bin 1.5.0.6 Gentoo dev-java/ibm-jdk-bin 1.4.2.10 BEA Systems JRockit 8.1 BEA Systems JRockit 8.0 BEA Systems JRockit 7.0 BEA Systems JRockit 3.1.5 BEA Systems JRockit 3.1.4 .1 BEA Systems JRockit 3.1.4 BEA Systems JRockit 3.1.3 BEA Systems JRockit 3.1.2 BEA Systems JRockit 3.1.1 BEA Systems JRockit 1.4.2 BEA Systems JRockit 1.4.2 R4.5 Avaya Interactive Response 2.0 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 |
| Not Vulnerable: |
Sun SDK (Windows Production Release) 1.4.2_14 Sun SDK (Solaris Production Release) 1.4.2_14 Sun SDK (Linux Production Release) 1.4.2_14 Sun JRE (Windows Production Release) 1.4.2_14 Sun JRE (Solaris Production Release) 1.4.2_14 Sun JRE (Linux Production Release) 1.4.2_14 Sun Java 2 Runtime Environment 5.0 Update 11 Gentoo dev-java/ibm-jre-bin 1.5.0.7 Gentoo dev-java/ibm-jre-bin 1.4.2.11 Gentoo dev-java/ibm-jdk-bin 1.5.0.7 Gentoo dev-java/ibm-jdk-bin 1.4.2.11 BEA Systems JRockit 1.4.2 07 BEA Systems JRockit 1.3.1 20 BEA Systems JRockit 1.5.0_04 |
Discussion
Sun Java Web Start Unauthorized Access Vulnerability
Sun Java Web Start is prone to a vulnerability that may allow remote attackers to gain unauthorized access to a vulnerable computer.
The vendor has reported that this vulnerability allows untrusted applications to gain read/write privileges to local files on a vulnerable computer.
The following versions for Windows, Solaris, and Linux platforms are vulnerable:
Java Web Start in JDK and JRE 5.0 Update 10 and earlier
Java Web Start in SDK and JRE 1.4.2_13 and earlier
Sun Java Web Start is prone to a vulnerability that may allow remote attackers to gain unauthorized access to a vulnerable computer.
The vendor has reported that this vulnerability allows untrusted applications to gain read/write privileges to local files on a vulnerable computer.
The following versions for Windows, Solaris, and Linux platforms are vulnerable:
Java Web Start in JDK and JRE 5.0 Update 10 and earlier
Java Web Start in SDK and JRE 1.4.2_13 and earlier
Exploit / POC
Sun Java Web Start Unauthorized Access Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Sun Java Web Start Unauthorized Access Vulnerability
Solution:
The vendor has released an update with fixes to address this issue.
BEA Systems JRockit 1.4.2 R4.5
Apple Mac OS X 10.4.10
Apple Mac OS X Server 10.4.10
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Solution:
The vendor has released an update with fixes to address this issue.
BEA Systems JRockit 1.4.2 R4.5
-
BEA Systems CR310095_CR318640_CR315192_JR-R24.5_1.4.2_08_linux32.tar.gz
ftp://anonymous:dev2dev%[email protected]/pub/releases/security/ CR310095_CR318640_CR315192_JR-R24.5_1.4.2_08_linux32.tar.gz
Apple Mac OS X 10.4.10
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
Apple Mac OS X Server 10.4.10
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
Apple Mac OS X 10.4.11
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
Apple Mac OS X Server 10.4.11
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
References
Sun Java Web Start Unauthorized Access Vulnerability
References:
References:
- CVE Request: python-rsa signature forgery (Filippo Valsorda )
- ASA-2007-199 - Security Vulnerability With Java Web Start Related to Incorrect U (Avaya)
- RHSA-2007:0817-2 - Critical: java-1.4.2-ibm security update (RedHat)
- RHSA-2007:0829-2 - Critical: java-1.5.0-ibm security update (RedHat)
- Sun Alert ID: 102881 (Sun)
- RHSA-2008:0261-4 Moderate: Red Hat Network Satellite Server security update (Red Hat)
- RHSA-2008:0524-4 Red Hat Network Satellite Server security update (Red Hat)