Sun Java SE Secure Static Versioning Applet Execution Weakness
BID:30142
Info
Sun Java SE Secure Static Versioning Applet Execution Weakness
| Bugtraq ID: | 30142 |
| Class: | Design Error |
| CVE: |
CVE-2008-3115 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 2008 12:00AM |
| Updated: | May 07 2015 05:27PM |
| Credit: | John Heasman |
| Vulnerable: |
VMWare VirtualCenter 2.0.2 VMWare VirtualCenter 2.5 Update 5 VMWare VirtualCenter 2.5 Update 2 VMWare VirtualCenter 2.5 Update 1 VMWare VirtualCenter 2.5 VMWare VirtualCenter 2.0.2 Update 5 VMWare VirtualCenter 2.0.2 Update 4 VMWare VirtualCenter 2.0.2 Update 3 VMWare VirtualCenter 2.0.2 Update 2 VMWare VirtualCenter 2.0.2 Update 1 VMWare ESX Server 3.0.3 VMWare ESX Server 3.0.2 VMWare ESX Server 3.0.1 VMWare ESX Server 3.5 Sun JRE (Linux Production Release) 1.6 _06 Sun JRE (Linux Production Release) 1.6 _05 Sun JRE (Linux Production Release) 1.6 _04 Sun JRE (Linux Production Release) 1.5 _15 Sun JRE (Linux Production Release) 1.5 _07 Sun JRE (Linux Production Release) 1.5 _06 Sun JRE (Linux Production Release) 1.6.0_03 Sun JRE (Linux Production Release) 1.6.0_02 Sun JRE (Linux Production Release) 1.6.0_01 Sun JRE (Linux Production Release) 1.5.0_14 Sun JRE (Linux Production Release) 1.5.0_13 Sun JRE (Linux Production Release) 1.5.0_12 Sun JRE (Linux Production Release) 1.5.0_11 Sun JRE (Linux Production Release) 1.5.0_10 Sun JRE (Linux Production Release) 1.5.0_09 Sun JRE (Linux Production Release) 1.5.0_08 Sun JDK (Linux Production Release) 1.6 _06 Sun JDK (Linux Production Release) 1.6 _05 Sun JDK (Linux Production Release) 1.6 _04 Sun JDK (Linux Production Release) 1.6 _01 Sun JDK (Linux Production Release) 1.6 Sun JDK (Linux Production Release) 1.5 0_10 Sun JDK (Linux Production Release) 1.5 _15 Sun JDK (Linux Production Release) 1.5 _14 Sun JDK (Linux Production Release) 1.5 _07 Sun JDK (Linux Production Release) 1.5 _06 Sun JDK (Linux Production Release) 1.6.0_03 Sun JDK (Linux Production Release) 1.6.0_02 Sun JDK (Linux Production Release) 1.5.0_13 Sun JDK (Linux Production Release) 1.5.0.0_12 Sun JDK (Linux Production Release) 1.5.0.0_11 Sun JDK (Linux Production Release) 1.5.0.0_09 Sun JDK (Linux Production Release) 1.5.0.0_08 Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Workstation 0 Nortel Networks Self-Service MPS 500 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service CCXML 0 Nortel Networks Self-Service 0 Nortel Networks Self Service VoiceXML 0 Nortel Networks MPS Speech Server 6.0 Nortel Networks MPS Manager 0 Nortel Networks MPS Developer 0 Nortel Networks MPS 3.0 Nortel Networks MPS 2.1 Nortel Networks MPS 1.0 Nortel Networks Enterprise VoIP TM-CS1000 Gentoo Linux Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.5 |
| Not Vulnerable: |
VMWare VirtualCenter 2.5.Update 3 build 1 Sun JRE (Linux Production Release) 1.6 _07 Sun JRE (Linux Production Release) 1.5 _16 Sun JDK (Linux Production Release) 1.6 _07 Sun JDK (Linux Production Release) 1.5.0_16 |
Discussion
Sun Java SE Secure Static Versioning Applet Execution Weakness
Sun JDK and JRE are prone to a weakness that may allow arbitrary applets to run on older releases of the software. This issue may lead to various attacks.
An attacker may exploit this weakness to potentially leverage vulnerabilities that may reside in older releases of the applications. This can lead to various attacks, depending on the presence of vulnerabilities in the older release of JDK/JRE on the vulnerable computer.
This issue affects the following versions on Windows VISTA:
JDK and JRE 6 Update 6 and earlier
JDK and JRE 5.0 Update 6 through 15
Sun JDK and JRE are prone to a weakness that may allow arbitrary applets to run on older releases of the software. This issue may lead to various attacks.
An attacker may exploit this weakness to potentially leverage vulnerabilities that may reside in older releases of the applications. This can lead to various attacks, depending on the presence of vulnerabilities in the older release of JDK/JRE on the vulnerable computer.
This issue affects the following versions on Windows VISTA:
JDK and JRE 6 Update 6 and earlier
JDK and JRE 5.0 Update 6 through 15
Exploit / POC
Sun Java SE Secure Static Versioning Applet Execution Weakness
Exploit code is not required to leverage this weakness.
Exploit code is not required to leverage this weakness.
Solution / Fix
Sun Java SE Secure Static Versioning Applet Execution Weakness
Solution:
Vendor advisory and fixes are available. Please see the references for more information.
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.5.4
Apple Mac OS X Server 10.5.4
Apple Mac OS X Server 10.5.5
Solution:
Vendor advisory and fixes are available. Please see the references for more information.
Apple Mac OS X 10.4.11
-
Apple JavaForMacOSX10.4Release7.dmg
Java for Mac OS X 10.4, Release 7
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=21278&cat= 59&platform=osx&method=sa/JavaForMacOSX10.4Release7.dmg
Apple Mac OS X Server 10.4.11
-
Apple JavaForMacOSX10.4Release7.dmg
Java for Mac OS X 10.4, Release 7
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=21278&cat= 59&platform=osx&method=sa/JavaForMacOSX10.4Release7.dmg
Apple Mac OS X 10.5.4
-
Apple JavaForMacOSX10.5Update2.dmg
Java for Mac OS X 10.5 Update 2
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=21277&cat= 59&platform=osx&method=sa/JavaForMacOSX10.5Update2.dmg
Apple Mac OS X Server 10.5.4
-
Apple JavaForMacOSX10.5Update2.dmg
Java for Mac OS X 10.5 Update 2
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=21277&cat= 59&platform=osx&method=sa/JavaForMacOSX10.5Update2.dmg
Apple Mac OS X Server 10.5.5
-
Apple JavaForMacOSX10.5Update2.dmg
Java for Mac OS X 10.5 Update 2
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=21277&cat= 59&platform=osx&method=sa/JavaForMacOSX10.5Update2.dmg
References
Sun Java SE Secure Static Versioning Applet Execution Weakness
References:
References: