Microsoft JVM INativeServices Unauthorized Memory Access Vulnerability
BID:6140
Info
Microsoft JVM INativeServices Unauthorized Memory Access Vulnerability
| Bugtraq ID: | 6140 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2002 12:00AM |
| Updated: | Nov 08 2002 12:00AM |
| Credit: | Discovered by Jouko Pynnonen <[email protected]>. |
| Vulnerable: |
Microsoft JVM 1.1 |
| Not Vulnerable: | |
Discussion
Microsoft JVM INativeServices Unauthorized Memory Access Vulnerability
A vulnerability has been reported in the Microsoft JVM INativeServices methods that may lead to unauthorized access to memory on a client system.
INativeServices methods accept memory addresses as parameters. Due to insufficient checking of these values, it may be possible to pass invalid memory addresses and cause a denial of service. Additionally, the pGetFontEnumeratedFamily() methods may also be invoked to read memory via vulnerable INativeServices methods. This may lead to disclosure of various types of sensitive information such as websites visited, cookies, and filesystem information such as the location of the cache directory.
It is possible for a Java applet to access INativeServices methods directly or indirectly through various other methods.
Exploitation of this vulnerability may facilitate other attacks, potentially leading to further information disclosure or execution of malicious code.
A vulnerability has been reported in the Microsoft JVM INativeServices methods that may lead to unauthorized access to memory on a client system.
INativeServices methods accept memory addresses as parameters. Due to insufficient checking of these values, it may be possible to pass invalid memory addresses and cause a denial of service. Additionally, the pGetFontEnumeratedFamily() methods may also be invoked to read memory via vulnerable INativeServices methods. This may lead to disclosure of various types of sensitive information such as websites visited, cookies, and filesystem information such as the location of the cache directory.
It is possible for a Java applet to access INativeServices methods directly or indirectly through various other methods.
Exploitation of this vulnerability may facilitate other attacks, potentially leading to further information disclosure or execution of malicious code.
Exploit / POC
Microsoft JVM INativeServices Unauthorized Memory Access Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft JVM INativeServices Unauthorized Memory Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft JVM INativeServices Unauthorized Memory Access Vulnerability
References:
References:
- Technical information about unpatched MS Java vulnerabilities (Jouko Pynnonen
)