漏洞信息详情
Java Web Start远程代码注入漏洞
漏洞简介
Java Web Start是用于简化在客户端部署Java应用程序的技术。
Java Web Start中的漏洞可能允许不可信任的应用程序提升权限,这样,应用程序就可以读写运行Java Web Start用户可以访问的本地文件,或执行该用户可访问的本地应用程序。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Sun Java 2 Runtime Environment 1.3 _05
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun JRE (Solaris Production Release) 1.3 _03
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun JRE (Solaris Production Release) 1.3 _04
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun JRE (Solaris Production Release) 1.3 _01
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun JRE (Solaris Production Release) 1.3.1
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun Java 2 Runtime Environment 1.3.1 _08
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun JRE (Linux Production Release) 1.3.1 _04
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun JRE (Linux Production Release) 1.3.1 _01a
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun Java 2 Runtime Environment 1.3.1 _01
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun Java 2 Runtime Environment 1.4.1
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun Java 2 Runtime Environment 1.4.2 _03
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun Java 2 Runtime Environment 1.4.2
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun Java 2 Runtime Environment 1.4.2 _02
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Sun Java 2 Runtime Environment 1.4.2 _04
Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp
Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html
Apple Mac OS X Server 10.3.4
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X 10.3.4
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X Server 10.3.5
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X 10.3.5
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X Server 10.3.6
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X 10.3.6
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X Server 10.3.7
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X 10.3.8
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dmg
Apple Mac OS X Server 10.3.8
Apple SecUpd2005-002Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=05426&plat form=osx&method=sa/SecUpd2005-002Pan.dm
参考网址
来源: BID
名称: 12847
链接:http://www.securityfocus.com/bid/12847
来源: GENTOO
名称: GLSA-200503-28
链接:http://www.gentoo.org/security/en/glsa/glsa-200503-28.xml
来源: SUNALERT
名称: 57740
链接:http://sunsolve.sun.com/search/document.do?assetkey=1-26-57740-1
来源: SECUNIA
名称: 14640
链接:http://secunia.com/advisories/14640
来源: FULLDISC
名称: 20050318 Java Web Start argument injection vulnerability
链接:http://marc.theaimsgroup.com/?l=full-disclosure&m=111117284323657&w=2
来源: MISC
链接:http://jouko.iki.fi/adv/ws.html
来源: SUSE
名称: SUSE-SA:2005:032
链接:http://www.novell.com/linux/security/advisories/2005_32_java2.html
受影响实体
- Sun J2se:1.4.2:Sdk<!--2000-1-1-->
- Sun J2se:1.4.2_01:Sdk<!--2000-1-1-->
- Sun J2se:1.4.2_02:Sdk<!--2000-1-1-->
- Sun J2se:1.4.2_03:Sdk<!--2000-1-1-->
- Sun J2se:1.4.2_04:Sdk<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...