Sun patches critical JRE security flaws

By Dawn Kawamoto, CNET News.com
Friday, January 19, 2007 11:15 AM

Sun Microsystems has issued a critical security patch to address vulnerabilities in Sun's Java Runtime Environment when it processes graphics interchange format, or GIF, images.

The security flaws could allow an attacker to gain control of a user's system via an untrusted Java applet, which in turn could allow attackers to grant themselves permission to read and write local files or execute applications on the user's computer, according to an advisory issued by Secunia on Wednesday.

Exploitation of these vulnerabilities, however, requires a user to visit a malicious Web site, as noted by Zero Day Initiative, which reported the vulnerability with the aid of an anonymous researcher.

The security flaws affect Sun's Java Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 update 9 and earlier, Software Development Kit (SDK) and JRE 1.4.2_12 and earlier; as well as SDK and JRE 1.3.1_18 and earlier for the Windows, Linux and Solaris platforms, according to an advisory issued by Sun on Wednesday.

Sun issued several patches to address the problem, which is somewhat similar to previous security flaws found in JRE.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Save changes to all open Word documents at one time

Microsoft Office Suite

If your Word sessions often wind up with a lot of open documents, this obscure command can streamline the process of closing them and saving your changes.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web