search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Sun Java Plug-in fails to restrict access to private Java packages

Vulnerability Note VU#760344

Original Release Date: 2004-11-23 | Last Revised: 2004-11-23

Overview

There is a vulnerability in the Sun Java Plug-in that could allow a malicious Java applet to bypass restrictions for untrusted applets.

Description

The Java Plug-in is part of the Java 2 Runtime Environment (JRE) and establishes a framework for displaying Java applets within a web browser. There is a vulnerability in the Java Plug-in security framework that could allow a malicious applet to bypass restrictions for accessing private Java packages.

Java's built-in security framework is designed to prevent access to private Java packages that are used internally by the Java Virtual Machine (JVM). When a Java applet attempts to access one of these packages, an AccessControlException will be thrown indicating that the requested access is denied. However, a flaw in the security framework fails to prevent such access to these private Java packages via JavaScript code.

Impact

By convincing a victim to download and run a malicious Java applet, an intruder could read, write, and modify files on the system with privileges of the victim.

The reporter notes that some private Java packages contain classes that allow direct access to memory or provide methods that can modify private fields of Java objects. This could allow an intruder to disable the Java security manager.

Solution

Upgrade
Sun has issued an advisory which addresses this issue. For more information on upgrades available for your system, please refer to Sun Security Alert 57591.

Vendor Information

760344
 

Sun Microsystems Inc. Affected

Updated:  November 23, 2004

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

Please refer to Sun Security Alert 57591.

If you have feedback, comments, or additional information about this vulnerability, please send us email.


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was reported by Jouko Pynnonen.

This document was written by Damon Morda.

Other Information

CVE IDs: CVE-2004-1029
Severity Metric: 17.55
Date Public: 2004-11-22
Date First Published: 2004-11-23
Date Last Updated: 2004-11-23 21:47 UTC
Document Revision: 25

Sponsored by CISA.