Microsoft JVM HTML Applet Tag Class Restriction Bypass Vulnerability
BID:6136
Info
Microsoft JVM HTML Applet Tag Class Restriction Bypass Vulnerability
| Bugtraq ID: | 6136 |
| Class: | Design Error |
| CVE: |
CVE-2002-1295 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2002 12:00AM |
| Updated: | Jul 11 2009 06:07PM |
| Credit: | Discovered by Jouko Pynnonen <[email protected]>. |
| Vulnerable: |
Microsoft JVM 1.1 |
| Not Vulnerable: | |
Discussion
Microsoft JVM HTML Applet Tag Class Restriction Bypass Vulnerability
A vulnerability has been reported in Microsoft JVM that may lead to a denial of service in Microsoft Internet Explorer.
It is possible to abuse the HTML <applet> tag to bypass Java class restrictions. Class objects may be instantiated using the HTML <applet> tag, and since this is not expected by the browser when some native methods are used, this may crash the browser.
A vulnerability has been reported in Microsoft JVM that may lead to a denial of service in Microsoft Internet Explorer.
It is possible to abuse the HTML <applet> tag to bypass Java class restrictions. Class objects may be instantiated using the HTML <applet> tag, and since this is not expected by the browser when some native methods are used, this may crash the browser.
References
Microsoft JVM HTML Applet Tag Class Restriction Bypass Vulnerability
References:
References:
- Technical information about unpatched MS Java vulnerabilities (Jouko Pynnonen
)