New Java exploits brewing

Powered by SC Magazine
 

Malicious code targets runtime software and development kits.

Attackers have released exploit code targeting two previously patched flaws in Sun Microsystems' Java Runtime Environment (JRE) and Java Software Development Kit (SDK). 

The flaws could allow an attacker to remotely execute code on a Windows, Linux or Solaris system. Sun issued patches for both vulnerabilities in December.

The JRE component allows JavaScript code to be executed on most operating systems, including Windows, Mac OS, Linux and Unix.

The vulnerabilities affect JRE 1.3.x, 1.4.x and 1.5.x, as well as versions 1.3.x and 1.4.x of the SDK and versions 1.5.x of the Java Development Kit.

Danish security vendor Secunia rates one of the vulnerabilities as 'highly critical', the company's second-highest level, owing to the possibility for remote code execution. 

Eric Sites, vice president of research and development at Sunbelt Software, told vnunet.com that, although exploits against Java vulnerabilities are uncommon, they do still pop up. 

"Sun has been very thorough and steady in the stuff it implements and how fast it implements it," he said.

Sites pointed out that Java is inherently a more secure system, because JRE uses so-called sandboxing that allows it to operate as a virtual machine to block access to other parts of the system.

He warned, however, that as developers create JavaScript applications that require more capabilities, they begin to call up .dll files from the system.

As soon as the programs reach outside the virtual machine for system files, the security protection of the sandbox is negated.

Sites said that this latest exploit is particularly worrying, as the code could be embedded in a small Java application that launches from a browser window and could deliver a malicious payload very quickly.

Copyright ©v3.co.uk


New Java exploits brewing
 
 
 
Top Stories
Beyond ACORN: Cracking the infosec skills nut
[Blog post] Could the Government's cybercrime focus be a catalyst for change?
 
The iTnews Benchmark Awards
Meet the best of the best.
 
Telstra hands over copper, HFC in new $11bn NBN deal
Value of 2011 deal remains intact.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  39%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  7%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  20%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  6%
TOTAL VOTES: 1787

Vote
Do you support the abolition of the Office of the Information Commissioner?