Sun JRE Arbitrary Command Execution Vulnerability
BID:2414
Info
Sun JRE Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 2414 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 21 2001 12:00AM |
| Updated: | Feb 21 2001 12:00AM |
| Credit: | This problem was first announced to Bugtraq in a Sun Security Advisory dated February 21, 2001, and was originally discovered by Pascal Brisset. |
| Vulnerable: |
Sun SDK (Windows Production Release) 1.3 .0_02 Sun SDK (Windows Production Release) 1.2.2 _007 Sun SDK (Windows Production Release) 1.2.1 Sun SDK (Windows Production Release) 1.2 Sun SDK (Solaris Reference Release) 1.2.2 _007 Sun SDK (Solaris Reference Release) 1.2.1 Sun SDK (Solaris Reference Release) 1.2 Sun SDK (Solaris Production Release) 1.3 .0_02 Sun SDK (Solaris Production Release) 1.2.2 _07 Sun SDK (Solaris Production Release) 1.2.2 _05a Sun SDK (Solaris Production Release) 1.2.1 Sun SDK (Solaris Production Release) 1.2 Sun SDK (Reference Release) 1.2.2 _005 Sun SDK (Reference Release) 1.2.1 _003 Sun SDK (Linux Production Release) 1.3 .0_02 Sun SDK (Linux Production Release) 1.2.2 _007 Sun SDK (Linux Production Release) 1.2.2 _005 Sun JRE (Windows Production Release) 1.3 .0_02 Sun JRE (Windows Production Release) 1.2.2 _007 Sun JRE (Windows Production Release) 1.2.1 Sun JRE (Windows Production Release) 1.2 Sun JRE (Solaris Reference Release) 1.2.2 _007 Sun JRE (Solaris Reference Release) 1.2.1 Sun JRE (Solaris Reference Release) 1.2 Sun JRE (Solaris Production Release) 1.3 .0_02 Sun JRE (Solaris Production Release) 1.2.2 _07 Sun JRE (Solaris Production Release) 1.2.2 _05a Sun JRE (Solaris Production Release) 1.2.1 Sun JRE (Solaris Production Release) 1.2 Sun JRE (Solaris Production Release) 1.1.8 _10 Sun JRE (Solaris Production Release) 1.1.7 B Sun JRE (Solaris Production Release) 1.1.6 Sun JRE (Reference Release) 1.2.2 _005 Sun JRE (Reference Release) 1.2.1 _003 Sun JRE (Reference Release) 1.1.8 _003 Sun JRE (Reference Release) 1.1.7 B_005 Sun JRE (Reference Release) 1.1.6 _007 Sun JRE (Linux Production Release) 1.3 .0_02 Sun JRE (Linux Production Release) 1.3 .0_01 Sun JRE (Linux Production Release) 1.3 .0 Sun JRE (Linux Production Release) 1.2.2 _007 Sun JRE (Linux Production Release) 1.2.2 _006 Sun JRE (Linux Production Release) 1.2.2 _005 Sun JRE (Linux Production Release) 1.2.2 _004 Sun JRE (Linux Production Release) 1.2.2 _003 Sun JRE (Linux Production Release) 1.2.2 Sun JDK (Reference Release) 1.1.8 _003 Sun JDK (Reference Release) 1.1.7 B_005 Sun JDK (Reference Release) 1.1.6 _007 |
| Not Vulnerable: | |
Discussion
Sun JRE Arbitrary Command Execution Vulnerability
JRE is the Sun Java Runtime Environment, a minimal software packaged designed to allow the execution of Java. It is maintained and distributed by Sun Microsystems.
A problem in the JRE could allow for the arbitrary execution of commands. This problem does not affect the JRE until a user has granted access to the piece of java code to execute a command. Once access has been granted, it may be possible to embed and execute other commands in succession. However, the JRE is not vulnerable to this problem by default, and requires a user declaring trust in the malicious code to allow exploitation.
JRE is the Sun Java Runtime Environment, a minimal software packaged designed to allow the execution of Java. It is maintained and distributed by Sun Microsystems.
A problem in the JRE could allow for the arbitrary execution of commands. This problem does not affect the JRE until a user has granted access to the piece of java code to execute a command. Once access has been granted, it may be possible to embed and execute other commands in succession. However, the JRE is not vulnerable to this problem by default, and requires a user declaring trust in the malicious code to allow exploitation.
Solution / Fix
Sun JRE Arbitrary Command Execution Vulnerability
Solution:
Upgrades available:
Windows Production Releases
SDK and JRE 1.3.0_04 http://java.sun.com/j2se/1.3.0/
SDK and JRE 1.2.2_009 http://java.sun.com/products/jdk/1.2.2/
Solaris OE Reference Releases
SDK and JRE 1.2.2_009 http://java.sun.com/products/jdk/1.2.2/
Solaris OE Production Releases
SDK and JRE 1.3.0_04 http://java.sun.com/j2se/1.3.0/
SDK and JRE 1.2.2_09 http://java.sun.com/products/jdk/1.2.2/
Linux Production Releases
SDK and JRE 1.3.0_04 http://java.sun.com/j2se/1.3.0/
SDK and JRE 1.2.2_009 http://java.sun.com/products/jdk/1.2.2/
Sun JRE (Solaris Production Release) 1.1.6
Sun JDK (Reference Release) 1.1.6 _007
Sun JRE (Reference Release) 1.1.6 _007
Sun JDK (Reference Release) 1.1.7 B_005
Sun JRE (Solaris Production Release) 1.1.7 B
Sun JRE (Reference Release) 1.1.7 B_005
Sun JRE (Reference Release) 1.1.8 _003
Sun JRE (Solaris Production Release) 1.1.8 _10
Sun JDK (Reference Release) 1.1.8 _003
Sun SDK (Reference Release) 1.2.1 _003
Sun JRE (Reference Release) 1.2.1 _003
Sun JRE (Reference Release) 1.2.2 _005
Sun SDK (Linux Production Release) 1.2.2 _005
Sun SDK (Reference Release) 1.2.2 _005
Sun SDK (Solaris Production Release) 1.2.2 _05a
Sun JRE (Solaris Production Release) 1.2.2 _05a
Sun JRE (Linux Production Release) 1.2.2 _005
Solution:
Upgrades available:
Windows Production Releases
SDK and JRE 1.3.0_04 http://java.sun.com/j2se/1.3.0/
SDK and JRE 1.2.2_009 http://java.sun.com/products/jdk/1.2.2/
Solaris OE Reference Releases
SDK and JRE 1.2.2_009 http://java.sun.com/products/jdk/1.2.2/
Solaris OE Production Releases
SDK and JRE 1.3.0_04 http://java.sun.com/j2se/1.3.0/
SDK and JRE 1.2.2_09 http://java.sun.com/products/jdk/1.2.2/
Linux Production Releases
SDK and JRE 1.3.0_04 http://java.sun.com/j2se/1.3.0/
SDK and JRE 1.2.2_009 http://java.sun.com/products/jdk/1.2.2/
Sun JRE (Solaris Production Release) 1.1.6
-
Sun JDK and JRE 1.1.8_12 Solaris Production Releases
http://www.sun.com/software/solaris/java/archive.html
Sun JDK (Reference Release) 1.1.6 _007
-
Sun JDK and JRE 1.1.6_009 Windows Production and Solaris Reference Releases
http://java.sun.com/products/jdk/1.1.6/
Sun JRE (Reference Release) 1.1.6 _007
-
Sun JDK and JRE 1.1.6_009 Windows Production and Solaris Reference Releases
http://java.sun.com/products/jdk/1.1.6/
Sun JDK (Reference Release) 1.1.7 B_005
-
Sun JDK and JRE 1.1.7B_007 Windows Production and Solaris Reference Releases
http://java.sun.com/products/jdk/1.1.7B/
Sun JRE (Solaris Production Release) 1.1.7 B
-
Sun JDK and JRE 1.1.8_12 Solaris Production Releases
http://www.sun.com/software/solaris/java/archive.html
Sun JRE (Reference Release) 1.1.7 B_005
-
Sun JDK and JRE 1.1.7B_007 Windows Production and Solaris Reference Releases
http://java.sun.com/products/jdk/1.1.7B/
Sun JRE (Reference Release) 1.1.8 _003
-
Sun JDK and JRE 1.1.8_006 Windows Production and Solaris Reference Releases
http://java.sun.com/products/jdk/1.1/
Sun JRE (Solaris Production Release) 1.1.8 _10
-
Sun JDK and JRE 1.1.8_12 Solaris Production Releases
http://www.sun.com/software/solaris/java/archive.html
Sun JDK (Reference Release) 1.1.8 _003
-
Sun JDK and JRE 1.1.8_006 Windows Production and Solaris Reference Releases
http://java.sun.com/products/jdk/1.1/
Sun SDK (Reference Release) 1.2.1 _003
-
Sun SDK and JRE 1.2.1_004 Windows Production and Solaris Reference Releases
http://java.sun.com/products/jdk/1.2.1/
Sun JRE (Reference Release) 1.2.1 _003
-
Sun SDK and JRE 1.2.1_004 Windows Production and Solaris Reference Releases
http://java.sun.com/products/jdk/1.2.1/
Sun JRE (Reference Release) 1.2.2 _005
-
Sun SDK and JRE 1.2.2_007 Windows Production and Solaris Reference Releases
http://java.sun.com/products/jdk/1.2/
Sun SDK (Linux Production Release) 1.2.2 _005
-
Sun SDK and JRE 1.2.2_007 Linux Production Release
http://java.sun.com/products/jdk/1.2/download-linux.html
Sun SDK (Reference Release) 1.2.2 _005
-
Sun SDK and JRE 1.2.2_007 Windows Production and Solaris Reference Releases
http://java.sun.com/products/jdk/1.2/
Sun SDK (Solaris Production Release) 1.2.2 _05a
-
Sun SDK and JRE 1.2.2_07 Solaris Production Releases
http://www.sun.com/software/solaris/java/download.html
Sun JRE (Solaris Production Release) 1.2.2 _05a
-
Sun SDK and JRE 1.2.2_07 Solaris Production Releases
http://www.sun.com/software/solaris/java/download.html
Sun JRE (Linux Production Release) 1.2.2 _005
-
Sun SDK and JRE 1.2.2_007 Linux Production Release
http://java.sun.com/products/jdk/1.2/download-linux.html