Sun patches flaw vulnerable to malicious image files

By
Follow google news

A flaw has been reported in Sun Microsystems Java Runtime Environment that can be exploited by a malicious user to compromise an affected system.


The flaw is caused by an error when processing GIF image files. Attackers can exploit the vulnerability to cause a heap-based buffer overflow through a specially-created malicious image file.

Vulnerability tracking firm Secunia has rated the flaw "highly critical," meaning it can be exploited without user interaction, but there are no known exploits in the wild.

The flaw exists in DJK and JRE Update 9 and earlier, SDK and JRE 1.4.2_12 and earlier and SDK and JRE 1.3.1_18 and earlier, and was first reported to Sun in June, according to 3Com's Zero Day Initiative.

Sun released a patch for the flaw on Tuesday, according to a company security advisory.

Click here to email Online Editor Frank Washkuch Jr.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

CBA chief impersonated in global investment fraud on Facebook

CBA chief impersonated in global investment fraud on Facebook

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Log In

  |  Forgot your password?