Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-Disclosure] Re: Sun Java Plugin arbitrary package access vulnerability |
|---|---|
| Date: | Thu, 25 Nov 2004 11:33:03 +0100 |
Jouko Pynnonen wrote:
A vulnerability in Java Plugin allows an attacker to create an Applet which can disable Java's security restrictions and break out of the Java sandbox.
<skip>
The Java Plugin versions 1.4.2_04 and 1.4.2_05 were tested on Windows and Linux. Web browsers tested were Microsoft Internet Explorer, Mozilla Firefox and Opera. It should be noted that Opera uses a different way of connecting JavaScript and Java which caused the test exploit not to work on Opera. However the problem itself (access to private packages) was demonstrated on Opera too, so it may be vulnerable to a variation of the exploit.
Alla.
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Router ZyXEL Prestige 650 HW http remote admin., Laurent Papier |
|---|---|
| Next by Date: | STG Security Advisory: [SSA-20041122-12] Zwiki XSS vulnerability, advisory |
| Previous by Thread: | Re: Sun Java Plugin arbitrary package access vulnerability, Ken S |
| Next by Thread: | Re: [Full-Disclosure] Re: Sun Java Plugin arbitrary package access vulnerability, Exchange |
| Indexes: | [Date] [Thread] [Top] [All Lists] |