Apple Mac OS X Java Plug-in 'file://' URL Handling Remote Code Execution Vulnerability
BID:31380
Info
Apple Mac OS X Java Plug-in 'file://' URL Handling Remote Code Execution Vulnerability
| Bugtraq ID: | 31380 |
| Class: | Design Error |
| CVE: |
CVE-2008-3638 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2008 12:00AM |
| Updated: | Sep 25 2008 04:19PM |
| Credit: | Nitesh Dhanjani and Billy Rios |
| Vulnerable: |
Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.5 |
| Not Vulnerable: | |
Discussion
Apple Mac OS X Java Plug-in 'file://' URL Handling Remote Code Execution Vulnerability
Apple Mac OS X Java plug-in is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by enticing an unsuspecting victim to visit a malicious webpage containing crafted Java applets.
Successfully exploiting this issue will allow attackers to run arbitrary code by launching arbitrary executables within the context of the affected application.
This issue affects Mac OS X 10.5.5 (and prior versions) and Mac OS X Server 10.5.5 (and prior versions).
Apple Mac OS X Java plug-in is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by enticing an unsuspecting victim to visit a malicious webpage containing crafted Java applets.
Successfully exploiting this issue will allow attackers to run arbitrary code by launching arbitrary executables within the context of the affected application.
This issue affects Mac OS X 10.5.5 (and prior versions) and Mac OS X Server 10.5.5 (and prior versions).
Exploit / POC
Apple Mac OS X Java Plug-in 'file://' URL Handling Remote Code Execution Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to visit a malicious webpage.
An attacker can exploit this issue by enticing an unsuspecting victim to visit a malicious webpage.
Solution / Fix
Apple Mac OS X Java Plug-in 'file://' URL Handling Remote Code Execution Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Apple Mac OS X 10.5.4
Apple Mac OS X Server 10.5.4
Apple Mac OS X 10.5.5
Apple Mac OS X Server 10.5.5
Solution:
The vendor has released an update. Please see the references for more information.
Apple Mac OS X 10.5.4
-
Apple JavaForMacOSX10.5Update2.dmg
Java for Mac OS X 10.5 Update 2
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=21277&cat= 59&platform=osx&method=sa/JavaForMacOSX10.5Update2.dmg
Apple Mac OS X Server 10.5.4
-
Apple JavaForMacOSX10.5Update2.dmg
Java for Mac OS X 10.5 Update 2
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=21277&cat= 59&platform=osx&method=sa/JavaForMacOSX10.5Update2.dmg
Apple Mac OS X 10.5.5
-
Apple JavaForMacOSX10.5Update2.dmg
Java for Mac OS X 10.5 Update 2
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=21277&cat= 59&platform=osx&method=sa/JavaForMacOSX10.5Update2.dmg
Apple Mac OS X Server 10.5.5
-
Apple JavaForMacOSX10.5Update2.dmg
Java for Mac OS X 10.5 Update 2
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=21277&cat= 59&platform=osx&method=sa/JavaForMacOSX10.5Update2.dmg
References
Apple Mac OS X Java Plug-in 'file://' URL Handling Remote Code Execution Vulnerability
References:
References:
- Mac OS X Homepage (Apple)