CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image Java Runtime Environment Remote Denial-of-Service (DoS) Vulnerability image
Security Hole
mowgreen writes "http://classic.sunsolve.sun.com/pub-cgi...2Asecurity

Sun Alert ID: 57707
* Synopsis: Java Runtime Environment Remote Denial-of-Service (DoS) Vulnerability
* Category: Security
* Product: Java SDK and JRE
* BugIDs: 5037001
* Avoidance: Upgrade
* State: Resolved
* Date Released: 20-Dec-2004
* Date Closed: 20-Dec-2004
* Date Modified:

1. Impact


A vulnerability in the Java Runtime Environment (JRE) involving object deserialization could be exploited remotely to cause the Java Virtual Machine to become unresponsive, which is a type of Denial-of-Service (DoS). This issue can affect the JRE if an application that runs on it accepts serialized data from an untrusted source.

Sun acknowledges with thanks, Marc Schoenefeld, for bringing this issue to our attention.
2. Contributing Factors

This issue can occur in the following releases:

* SDK and JRE 1.4.2_05 and earlier, and all 1.4.1 and 1.4.0 releases for Windows, Solaris and Linux

Note: JDK and JRE 5.0 and releases prior to SDK and JRE 1.4 are not affected by this issue.

To determine the version of Java on a system, the following command can be run:

% java -fullversion
java full version 1.4.1_06-b01

3. Symptoms

The Java Runtime Environment (JRE) is unresponsive.
Solution Summary

4. Relief/Workaround

There is no workaround. Please see the Resolution section below.
5. Resolution

This issue is addressed in the following releases:

* SDK and JRE 1.4.2_06 and later for Windows, Solaris, and Linux

J2SE releases are available for download at:

* J2SE 5.0 at http://java.sun.com/j2se/1.5.0/download.jsp
* J2SE 1.4.2_06 at http://java.sun.com/j2se/1.4.2/download.html and http://java.com/

Note: It is recommended that affected versions be removed from your system. For more information, please see the installation notes on the respective java.sun.com download pages. "
Posted on Thursday, 06 January 2005 @ 17:22:09 UTC by Paul (2324 reads)
[ Trackback ]
image

"Java Runtime Environment Remote Denial-of-Service (DoS) Vulnerability" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Linux.com
· Microsoft
· HotScripts
· W3 Consortium
· More about Security Hole
· News by Paul


Most read story about Security Hole:
Windows Media Player, Spyware and Trojan

block bottom
Article Rating
spacer
Average Score: 5
Votes: 1


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer