Sun Java Virtual Machine Segmentation Violation Vulnerability
BID:3992
Info
Sun Java Virtual Machine Segmentation Violation Vulnerability
| Bugtraq ID: | 3992 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 30 2002 12:00AM |
| Updated: | Jan 30 2002 12:00AM |
| Credit: | Posted to the Bugtraq mailing list by Taeho Oh <[email protected]>. |
| Vulnerable: |
Sun JRE (Linux Production Release) 1.3.1 Sun JRE (Linux Production Release) 1.2.2 |
| Not Vulnerable: | |
Discussion
Sun Java Virtual Machine Segmentation Violation Vulnerability
Java programs run in an intepreted environment, the Java Virtual Machine (JVM). Sun has provided a reference JVM implementation for multiple platforms, including Solaris, Windows and Linux.
It is possible for a maliciously constructed, valid java program to crash the Sun JVM. This may result in a denial of service attack in a shared environment. The ability to consistantly exploit this vulnerability has been demonstrated on the Linux version of the Sun JVM.
Java programs run in an intepreted environment, the Java Virtual Machine (JVM). Sun has provided a reference JVM implementation for multiple platforms, including Solaris, Windows and Linux.
It is possible for a maliciously constructed, valid java program to crash the Sun JVM. This may result in a denial of service attack in a shared environment. The ability to consistantly exploit this vulnerability has been demonstrated on the Linux version of the Sun JVM.
Exploit / POC
Sun Java Virtual Machine Segmentation Violation Vulnerability
The following example has been provided by Taeho Oh <[email protected]>:
The following example has been provided by Taeho Oh <[email protected]>:
Solution / Fix
Sun Java Virtual Machine Segmentation Violation Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.