Java Plug-In 1.4/JRE 1.3 Expired Certificate Vulnerability
BID:3245
Info
Java Plug-In 1.4/JRE 1.3 Expired Certificate Vulnerability
| Bugtraq ID: | 3245 |
| Class: | Environment Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2001 12:00AM |
| Updated: | Aug 24 2001 12:00AM |
| Credit: | Discovered by Daniel Kasmeroglu <[email protected]>. |
| Vulnerable: |
Sun Java Plug-In 1.4 Sun Java 2 Runtime Environment 1.3 |
| Not Vulnerable: | |
Discussion
Java Plug-In 1.4/JRE 1.3 Expired Certificate Vulnerability
Java Plug-In is a product from Sun that allows for Java applets to be run in web browsers.
It has been reported that a vulnerability exists when Java Plug-In 1.4 is used on systems with Java Runtime Environment version 1.3 installed. Users may not be alerted by the plugin/JRE when applets have been signed with expired certificates. As a result, the user may be lead to believe that the applet is valid and allow it to be run on the local computer.
The existence of this vulnerability has not yet been confirmed by the vendor.
Java Plug-In is a product from Sun that allows for Java applets to be run in web browsers.
It has been reported that a vulnerability exists when Java Plug-In 1.4 is used on systems with Java Runtime Environment version 1.3 installed. Users may not be alerted by the plugin/JRE when applets have been signed with expired certificates. As a result, the user may be lead to believe that the applet is valid and allow it to be run on the local computer.
The existence of this vulnerability has not yet been confirmed by the vendor.
Exploit / POC
Java Plug-In 1.4/JRE 1.3 Expired Certificate Vulnerability
There is no specific exploit code required. To launch an attack using this vulnerability, an attacker may require a malicious applet, expired signature and ability to 'spoof' a trusted website.
There is no specific exploit code required. To launch an attack using this vulnerability, an attacker may require a malicious applet, expired signature and ability to 'spoof' a trusted website.
Solution / Fix
Java Plug-In 1.4/JRE 1.3 Expired Certificate Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.