Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2004-1029
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-1029

Description:
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/18188

SUNALERT
  http://sunsolve.sun.com/search/document.do?assetkey=1-26-57591-1
  http://sunsolve.sun.com/search/document.do?assetkey=1-26-101523-1

SREASON
  http://securityreason.com/securityalert/61

SAID
  Secunia Advisory: SA13271
  Secunia Advisory: SA29035

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5674

MISC
  http://jouko.iki.fi/adv/javaplugin.html

IDEFENSE
  http://www.idefense.com/application/poi/display?id=158&type=vulnerabilities

CONFIRM
  http://www-1.ibm.com/support/docview.wss?uid=swg21257249
  http://rpmfind.net/linux/RPM/suse/updates/9.3/i386/rpm/i586/java-1_4_2-sun-src-1.4.2.08-0.1.i586.html

CERT-VN
  760344

BID
  12317

APPLE
  http://lists.apple.com/archives/security-announce/2005/Feb/msg00000.html


Return to the previous page.