|
Java 2 Micro Edition (J2ME) Bytecode Verifier Code Execution Vulnerabilities
|
|
Secunia Advisory:
|
SA12945
|
|
|
Release Date:
|
2004-10-22
|
|
Popularity:
|
11,118 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Unpatched
|
|
| Software: | Java 2 Micro Edition (J2ME)
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
Description: Adam Gowdiak has reported two vulnerabilities in Java 2 Micro Edition (J2ME), which can be exploited by malicious people to compromise a vulnerable system.
The vulnerabilities are caused due to insufficient validation of bytecodes in the bytecode verifier component of KVM (Kilobyte Virtual Machine). This can be exploited to escape the KVM sandbox and execute arbitrary code on the mobile device.
The vulnerabilities have been reported on a Nokia DCT4 phone. Other devices may also be affected.
Solution: Do not run untrusted Java applications.
Provided and/or discovered by: Adam Gowdiak
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|