Zero day Java flaw opens up all users to attack

Powered by SC Magazine
 

Oracle's view is that it's no big deal.

Security researchers have warned of a flaw in Java that could allow malware writers to inject code onto user's machines.

The flaw is in the Java Web Start system built for developers with every version since Java 6 Update 10. The code contains a NPAPI plugin and ActiveX control called "Java Deployment Toolkit" which doesn't check the full parameters of URLs.

"The toolkit provides only minimal validation of the URL parameter, allowing us to pass arbitrary parameters to the javaws [Java Web Start] utility, which provides enough functionality via command line arguments to allow this error to be exploited," Tavis Ormandy wrote on the Full Disclosure mailing list.

"The simplicity with which this error can be discovered has convinced me that releasing this document is in the best interest of everyone except the vendor."

Ormandy said that the flaw opened up all Windows users of Java to attack. He published his findings because Oracle considered the bug not important enough to break its quarterly patching schedule.

“Sun has been informed about this vulnerability, however, they informed me they do not consider this vulnerability to be of high enough priority to break their quarterly patch cycle,” he posted.

“For various reasons, I explained that I did did not agree, and intended to publish advice to temporarily disable the affected control until a solution is available.”

Copyright ©v3.co.uk


Zero day Java flaw opens up all users to attack
Tags
 
 
 
Top Stories
The iTnews Benchmark Awards
Meet the best of the best.
 
Telstra hands over copper, HFC in new $11bn NBN deal
Value of 2011 deal remains intact.
 
Photos: iTnews Benchmark 2015 finalists revealed
Awards alumni gather to celebrate.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  39%
 
Your insurance company
  4%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  7%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  20%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  6%
TOTAL VOTES: 1746

Vote
Do you support the abolition of the Office of the Information Commissioner?