Sun Alert 270474 Buffer and Integer Overflow Vulnerabilities in the Java Runtime Environment With Processing Audio and Image Files May Allow Privileges to be Escalated
Product: Java Platform, Standard Edition 6 (Java SE 6)Multiple buffer and integer overflow vulnerabilities in the Java Runtime Environment with processing audio and image files may allow an untrusted applet or Java Web Start application to escalate privileges. For example, an untrusted applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet.Sun acknowledges with thanks, the following researchers for bringing these issues to our attention:CR ...

Product: Java Platform, Standard Edition 6 (Java SE 6)

Multiple buffer and integer overflow vulnerabilities in the Java Runtime Environment with processing audio and image files may allow an untrusted applet or Java Web Start application to escalate privileges. For example, an untrusted applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet.

Sun acknowledges with thanks, the following researchers for bringing these issues to our attention:

CR 6854303: An anonymous researcher, working withthe Zero Day Initiative (http://www.zerodayinitiative.com)and TippingPoint (http://www.tippingpoint.com).

CR 6862970: An anonymous researcher working with theiDefense VCP (http://labs.idefense.com/vcp/).

CR 6872357 and CR 6872358: Peter Vreugdenhil, working with the ZeroDay Initiative (http://www.zerodayinitiative.com)and TippingPoint (http://www.tippingpoint.com).

CR 6872358, CR 6862969 and CR 6862968: regenrecht working with iDefense VCP (http://labs.idefense.com/vcp/).

CR 6874643: regenrecht working with Zero DayInitiative (http://www.zerodayinitiative.com)and TippingPoint (http://www.tippingpoint.com).

State: Resolved
First released: 03-Nov-2009

Read Full Article

Written on Wednesday, 20 January 2010 19:00 by

Viewed 0 times so far.
Like this? Tweet it to your followers!

Rate this article

Latest articles from

Latest 'tweets' from GovernmentSecurity

blog comments powered by Disqus

 

Our Sponsors

Shoutcast Streams | Internet Radio HOSTINGLitespeed Web HostingIRC | IRCd | Internet Relay Chat HostingEarn Recurring Income

Member Login