Skip to main content

Sun Java Runtime Environment Remote Code Execution Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 11 Feb 2008 4534 Views

RISK: Medium Risk

Two vulnerabilities have been identified in Sun Java Runtime Environment, which could be exploited by remote attackers to take complete control of an affected system. These issues are caused by unspecified errors when handling certain untrusted applications or applets, which could be exploited by a malicious web site to cause a downloaded application or applet to elevate its privileges and grant itself permissions to read and write local files or execute local applications with the privileges of the logged-on user.


Impact

  • Elevation of Privilege

System / Technologies affected

  • JDK and JRE 6 Update 1 and earlier
  • JDK and JRE 5.0 Update 13 and earlier

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Update to the latest versions or apply patches.

JDK and JRE 6 Update 2 or later:
http://java.sun.com/javase/downloads/index.jsp

JDK and JRE 5.0 Update 14 or later:
http://java.sun.com/javase/downloads/index_jdk5.jsp


Vulnerability Identifier


Source


Related Link