On mySimon: BRITTO Butterfly Luggage
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Nov 23, 2004 8:43:00 PM

A flaw in Sun Microsystems' plug-in for running Java on a variety of browsers and operating systems could allow a virus to spread through Microsoft Windows and Linux PCs.

The vulnerability, found by Finnish security researcher Jouko Pynnonen in April, was patched last month by Sun, but its details were not made public until Tuesday. Security information provider Secunia posted information about the flaw in an advisory that rated it a "highly critical" threat.

The Java plug-in enables small Web programs, known as applets, to run safely on a user's computer. But the security flaw allows a malicious Web site accessed through a victim's browser to bypass those protections.

"It allows execution of attacker-supplied code without user interaction (apart from viewing a Web page) which usually means a 'critical' classification," Pynonnen stated in an e-mail interview with CNET News.com.

"The same exploit could also be used against various operating systems and browsers, which makes it more serious," he added. The vulnerability can be used to attack systems running on Windows or Linux, for example, and using major browser software such as Microsoft's Internet Explorer and Firefox--meaning a large number of systems are vulnerable to attack.

An attacker could use the flaw to do anything the victim normally could, including browse, modify or run files, upload more programs to the victim's system, or send out data from the system, Pynnonen wrote in an advisory dated Tuesday.

While the major browsers have had to deal with a significant number of security issues, the flaw is a rare black eye for the security of Sun's Java technology. Java is designed to be able to run programs downloaded from the Internet on various operating systems safely, without danger to a PC. The "sandbox" that cordons off Java applets from the rest of the system has typically worked well.

However, the flaw allows small snippets of Web code, known as Javascript, to execute functions of Java that were never meant to be run by external programs.

Last week, while announcing details of Sun's forthcoming Solaris 10 operating system, President Jonathan Schwartz noted that Java hasn't been afflicted by a single Java virus.

However, the new security hole could allow a virus to use the Java plug-in to invade PC systems. In October, a flaw in the Java plug-in for cell phones raised the specter that a malicious program disguised as a helpful application could attack a phone's software, if run by a user.

Like the recent iFrame vulnerability in Microsoft's Internet Explorer, the Java flaw could allow a malicious Web site to download and execute a program that would compromise a visitor's PC.

"It could be easily used for spreading viruses or other malware," Pynnonen said in the e-mail. "The exploit itself can't be easily embedded in e-mail, because Java applets contained in e-mail aren't normally started automatically. However an e-mail message could contain a link to a Web page which has the exploit."

While Sun would not speculate on how the flaw could be used by attackers, the company did say that it worked hard to distribute the patch for it to all users.

"We took this very seriously, and we have gone the extra mile to post these patches," a Sun representative said on Tuesday.

The advisories from Sun, Secunia and Pynnonen do not address whether the problem could affect Apple Computer's Mac OS X operating system, which is based on a Unix-like core of code, similar to Linux. The Sun representative said that the Mac issue is being investigated.

Apple Computer was not immediately available for comment.

CNET News.com's Stephen Shankland contributed to this report.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 91 Talkback(s)
You think?
Java is a *tiny* part of the whole that is not necessary to run the whole. Whereas the opposite is not true. e.g. A window in a car is useless without the door and/or body ... yep ... the window will ... (Read the rest)
Posted by: gary.douglas@... Posted on: 12/07/04 You are currently: a Guest | | Terms of Use
Film at 11:00  ShadeTree | 11/23/04
What?  doe_z | 11/23/04
Aww, ya fell for it!  Martin Marvinski | 11/24/04
linux and firefox?  Monkey_MCSE | 11/23/04
Well Said Monkey!  itanalyst | 11/23/04
I guess..  d_jedi | 11/24/04
Read it and here is the quote  ShadeTree | 11/23/04
you can read the full story  Monkey_MCSE | 11/23/04
It is not the IE or Windows crowds that...  ShadeTree | 11/23/04
in fact, both crowds have people  Monkey_MCSE | 11/23/04
Really?  Immanuel Tranz-Mischen | 11/23/04
Turning off the java reminder popups  Anton Philidor | 11/24/04
Depends if you are running as root  Harry Butts | 11/23/04
Hear hear!  Yen_z | 11/23/04
Are you sure?  PA-ITGuy | 11/23/04
Mr. Butts is correct  PA-ITGuy | 11/24/04
Better design?  NonZealot | 11/23/04
And, as usual,  AmusedAtItAll | 11/23/04
Consider yourself challenged  NonZealot | 11/23/04
Re: Consider yourself challenged  richdave | 11/23/04
I'm sorry  NonZealot | 11/24/04
can you tell me what most home users  Monkey_MCSE | 11/23/04
Finally a message worth putting some thought into  NonZealot | 11/23/04
Ah you try to flame... but only blow smoke!  Linux User 147560 | 11/23/04
You must be a terrible admin  NonZealot | 11/23/04
Reading comprehension  tic swayback | 11/23/04
Yes, let's talk about reading comprehension  NonZealot | 11/24/04
your still wrong  doh123 | 11/24/04
NonZealot is RIGHT!!!  DragonBRockin | 11/24/04
You're SURE you're not running as admin?  Michael Kelly | 11/24/04
Ahh, anecdotes...  Martin Marvinski | 11/24/04
Windows Permissions  wolf_z | 11/24/04
You sure like to hear yourself type!  NonZealot | 11/24/04
wolf  Martin Marvinski | 11/24/04
Irony is I am not an Admin!  Linux User 147560 | 11/24/04
Good, glad we could agree  NonZealot | 11/24/04
RE: Good glad we could agree  Linux User 147560 | 11/24/04
Non Zealot... here is a good read for you...  Linux User 147560 | 11/24/04
Sure you can run without admin privileges.  Immanuel Tranz-Mischen | 11/24/04
What is your defn of day to day work?  NonZealot | 11/24/04
Oops, forgot a couple  NonZealot | 11/24/04
Fantastic  Martin Marvinski | 11/24/04
RE: fantastic  NonZealot | 11/24/04
Either that or...  rapson | 11/24/04
Re: Film at 11:00  richdave | 11/23/04
Oh come on....  mobrien_12@... | 11/23/04
There's no Java in MY FireFox...  Jomo_z | 11/24/04
Hmm...nice flamebait.  Linux_Developer | 11/24/04
oh - And...  Linux_Developer | 11/24/04
Arrogance and incompetence  FilledOut | 11/23/04
by that logic  doh123 | 11/24/04
Or AOL or Oracle  FilledOut | 11/24/04
Microsoft version of Java?  duclod | 11/23/04
MS Java was discontinued  Monkey_MCSE | 11/23/04
Since when?  htotten | 11/23/04
facts are straight, but if you use VS  Monkey_MCSE | 11/23/04
You're talking about different stuff  seosamh_z | 11/23/04
Your post said MS stopped developing JAVA.  htotten | 11/23/04
and if you're going to quote  Monkey_MCSE | 11/23/04
This is an interesting question.  mobrien_12@... | 11/23/04
Microsoft's JVM  PA-ITGuy | 11/24/04
MS version had its own flaws  CobraA1 | 11/25/04
Why the secrecy?  rapson | 11/23/04
Could it be...  PA-ITGuy | 11/23/04
Well...  rapson | 11/23/04
And see what hapens  PA-ITGuy | 11/23/04
Heres the problem *I* see  supercharlie | 11/23/04
If you're running J2RE it does autoupdate.  PA-ITGuy | 11/23/04
Perhaps I should add  PA-ITGuy | 11/23/04
Not necessarily  rapson | 11/23/04
Re:Not necessarily  PA-ITGuy | 11/23/04
Carl, it's the end users who are affected  Anton Philidor | 11/24/04
re : and see what happens  JasonL31 | 11/24/04
What *should* happen..  d_jedi | 11/24/04
Well, how about...  AmusedAtItAll | 11/23/04
No kidding.  mobrien_12@... | 11/23/04
I agree  JasonL31 | 11/24/04
JPEG flaw was unpatched by MS for 10 months!  David Hamilton | 11/24/04
So a hex on both of their houses  FilledOut | 11/24/04
Almost...  David Hamilton | 11/24/04
YES  JasonL31 | 11/24/04
Why no "auto-update" on this patch?  TwangGuru | 11/27/04
Am I the only who has disabled Java?  Expatriate US Geek | 11/24/04
Why I use Firefox - rather off-topic  Martin Marvinski | 11/24/04
I completely agree..  d_jedi | 11/24/04
Nope  FilledOut | 11/24/04
YES  JasonL31 | 11/24/04
Wow, I could click on an ad in IE...  boomslang_z | 11/24/04
A taste of your own medicine?  ISD_z | 11/28/04
Someone please check the record... Sun 1... MS 1000000000  john.gruber@... | 11/28/04
You think?  gary.douglas@... | 12/07/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads