J2SE Java Web Start Client-Side Argument Injection Vulnerability
Monday, 21 March 2005 by Michel Roth
A critical vulnerability was identified in Java Web Start, which may allow an untrusted application the ability to elevate its privileges. The flaw resides in the Java Web Start launcher ("javaws.exe" for Windows and "javaws" for Solaris and Linux) when handling a specially crafted "property" tag in a "JNLP" file, which may be exploited, via a specially crafted web page, to bypass the default "sandbox" security policy and read/write arbitrary files on a vulnerable system.

Affected Products
Java Web Start in Java 2 Platform Standard Edition (J2SE) version 1.4.2_06 and earlier 1.4.2 releases for Windows, Solaris and Linux.
Note: Java Web Start in J2SE 5.0 and later and J2SE releases prior to 1.4.2 for Windows, Solaris and Linux are NOT affected by this issue. Java Web Start 1.0.1_02 and earlier are also NOT affected.

Solution
Upgrade to J2SE 1.4.2_07
Upgrade to J2SE 5.0 Update 2

Or disable Java Web Start applications from being launched from a web browser.

J2SE Java Web Start is automaticly installed when you install XP1.0 or MPS 3.0, so be sure to check if you need to update!

More info here.

Related Items:

Java Web Start / Sun JRE Sandbox Security Bypass Vulnerability (16 June 2005)
Citrix Presentation Server And MetaFrame Print Provider Buffer Overflow Vulnerability (24 January 2007)
McAfee Antivirus Products LHA Archive Stack Overflow Vulnerability (18 March 2005)
Security Updates Summary For May 2006 (9 May 2006)
Microsoft Windows "itss.dll" Heap Corruption Unpatched Vulnerability (10 May 2006)
Updated: Mozilla Firefox Two Critical Vulnerabilities (13 May 2005)
Virtualization To Transform IT, Says VMware Founder Mendel Rosenblum (14 March 2006)
Citrix On Daylight-saving Time Changes in 2007 (12 March 2007)
Trend Micro Products AntiVirus Library Buffer Overflow (27 February 2005)
0-Day Microsoft Excel Unspecified Code Execution Vulnerability (19 June 2006)
Comments (0)add feed
password
 

busy