Secunia Logo  


Secunia PSI WorldMap
 
Sun Java JDK / JRE Multiple Vulnerabilities
Secunia Advisory: SA34451
Release Date: 2009-03-26
Last Update: 2009-04-03
Popularity: 77,698 views

Critical:
Highly critical
Impact: Security Bypass
DoS
System access
Where: From remote
Solution Status: Vendor Patch

Software:Sun Java JDK 1.5.x
Sun Java JDK 1.6.x
Sun Java JRE 1.3.x
Sun Java JRE 1.4.x
Sun Java JRE 1.5.x / 5.x
Sun Java JRE 1.6.x / 6.x
Sun Java SDK 1.3.x
Sun Java SDK 1.4.x

Binary Analysis: BA704 :: Available for 1 Credit
BA703 :: Available for 1 Credit
BA702 :: Available for 1 Credit
BA705 :: Available for 1 Credit

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 1 of 3)[ 1 ] [ 2 ] [ 3 ]

Description:
Some vulnerabilities have been reported in Sun Java, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or potentially compromise a user's system.

1) An error while initialising LDAP connections can be exploited to render the LDAP service unresponsive.

2) An error in the JRE LDAP client implementation can be exploited to load and execute arbitrary code via specially crafted data received from a malicious LDAP server.

3) An integer overflow error in JRE when unpacking applets and in Java Web Start applications using the "unpack200" JAR unpacking utility can be exploited to potentially execute arbitrary code.

This is related to vulnerability #15 in:
SA32991

4) An error in JRE when unpacking applets and in Java Web Start applications using the "unpack200" JAR unpacking utility can be exploited to cause a buffer overflow and potentially execute arbitrary code.

5) Two errors when storing and processing temporary font files can be exploited by an untrusted applet or a Java Web Start application to consume an overly large amount of disk space.

This is related to:
SA20132

6) An error in the Java Plug-in when deserializing applets can be exploited to e.g. read, write, or execute local files.

7) The Java Plug-in allows JavaScript code loaded from the local system to connect to arbitrary local ports. This can be exploited in combination with cross-site scripting attacks to access normally restricted local ports.

8) The Java Plug-in allows applets to run in earlier versions of JRE if approved by the user. This can be exploited to trick a user into loading a malicious applet into an old and potentially vulnerable JRE version.

9) An error in the Java Plug-in when processing crossdomain.xml files can be exploited by an untrusted applet to connect to arbitrary domains providing a crossdomain.xml file.

10) An error in the Java Plug-in can be exploited by a signed applet to alter the contents of the security dialog and trick a user into trusting the applet.

11) An error in the JRE virtual machine when generating code can be exploited to e.g. read, write, or execute local files.

NOTE: This vulnerability only affects JDK and JRE 6 Update 12 and earlier for the Solaris SPARC platform.

12) An integer overflow error in JRE when processing PNG splash screen images can be exploited by an untrusted Java Web Start application to cause a buffer overflow and potentially execute arbitrary code.

13) An error in JRE when processing GIF splash screen images can be exploited by an untrusted Java Web Start application to cause a buffer overflow and potentially execute arbitrary code.

14) An error in JRE when processing GIF images can be exploited by an untrusted applet or an untrusted Java Web Start application to cause a buffer overflow and potentially execute arbitrary code.

15) A signedness error in JRE when processing Type1 fonts can be exploited to cause corrupt heap memory and potentially execute arbitrary code.

16) An unspecified error in the JRE HTTP server implementation can be exploited to render a JAX-WS service endpoint unresponsive.

Please see the vendor advisories for details on affected products and versions.

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Today
New advisories: 6
New vulnerabilities: 23
Updated advisories: 8

Not // 48 views
Debian update for pidgin
Less // 60 views
Debian update for linux-2.6
Less // 53 views
Debian update for drupal6
Highly // 51 views
Debian update for nspr

6th Nov, 2009
New advisories: 17
New vulnerabilities: 65
Updated advisories: 21

Less // 394 views
Debian update for linux-2.6.24
Less // 381 views
Debian update for linux-2.6
Moderately // 345 views
Gentoo update for horde

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Linux Kernel 2.4 Multiple Vulnerabilities // 66 views
2. Sun Solaris mod_perl Two Vulnerabilities // 64 views
3. Debian update for linux-2.6 // 57 views
4. Sun Java JDK / JRE Multiple Vulnerabilities // 57 views
5. Microsoft PowerPoint OutlineTextRefAtom Parsing Vulnerability // 48 views
6. Debian update for pidgin // 46 views
7. Google Chrome Two Vulnerabilities // 43 views
8. Debian update for drupal6 // 43 views
9. Debian update for nspr // 42 views
10. Mozilla Firefox Multiple Vulnerabilities // 30 views