Kaffe OpenVM NoClassDefFoundError Format String Vulnerability
BID:4249
Info
Kaffe OpenVM NoClassDefFoundError Format String Vulnerability
| Bugtraq ID: | 4249 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 25 2002 12:00AM |
| Updated: | Feb 25 2002 12:00AM |
| Credit: | Published by KF <[email protected]>. |
| Vulnerable: |
Kaffe Kaffe OpenVM 1.0.6 |
| Not Vulnerable: | |
Discussion
Kaffe OpenVM NoClassDefFoundError Format String Vulnerability
Kaffe OpenVM is a free, open source implementation of a Java Virtual Machine (JVM). Originally developed for Unix based systems, it is available for Windows as well as Linux and BSD based systems.
A vulnerability has been reported in some versions of the Kaffe JVM. When a java.lang.NoClassDefFoundError error is thrown, the class name in question is interpreted as a format string. If this issue is exploitable, it may be possible to entirely break any restrictions imposed by the Java security model.
Earlier versions of Kaffe may share this vulnerability. This has not, however, been confirmed.
Kaffe OpenVM is a free, open source implementation of a Java Virtual Machine (JVM). Originally developed for Unix based systems, it is available for Windows as well as Linux and BSD based systems.
A vulnerability has been reported in some versions of the Kaffe JVM. When a java.lang.NoClassDefFoundError error is thrown, the class name in question is interpreted as a format string. If this issue is exploitable, it may be possible to entirely break any restrictions imposed by the Java security model.
Earlier versions of Kaffe may share this vulnerability. This has not, however, been confirmed.
Solution / Fix
Kaffe OpenVM NoClassDefFoundError Format String Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.