ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Java flaw opens Windows, Linux to attack

Published: 24 Nov 2004 09:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A flaw in Sun's plug-in for running Java on a variety of browsers and operating systems could allow a virus to spread through Microsoft Windows and Linux PCs.

The vulnerability, found by Finnish security researcher Jouko Pynnonen in June, was patched last month by Sun, but its details were not made public until Tuesday. Security information provider Secunia posted information about the flaw in an advisory that rated it a "highly critical" threat.

The Java plug-in enables applets to run safely on a user's computer. But the security flaw allows a malicious Web site accessed through a victim's browser to bypass those protections.

"It allows execution of attacker-supplied code without user interaction [apart from viewing a Web page] which usually means a 'critical' classification," Pynonnen stated in an email interview with ZDNet UK sister site CNET News.com.

"The same exploit could also be used against various operating systems and browsers, which makes it more serious," he added. The vulnerability can be used to attack systems running on Windows or Linux, for example, and using major browser software such as Microsoft's Internet Explorer and Firefox -- meaning a large number of systems are vulnerable to attack.

An attacker could use the flaw to do anything the victim normally could, including browse, modify or run files, upload more programs to the victim's system, or send out data from the system, Pynnonen wrote in an advisory dated Tuesday.

While the major browsers have had to deal with a significant number of security issues, the flaw is a rare black eye for the security of Sun's Java technology. Java is designed to be able to run programs downloaded from the Internet on various operating systems safely, without danger to a PC. The "sandbox" that cordons off Java applets from the rest of the system has typically worked well.

However, the flaw allows small snippets of Web code, known as Javascript, to execute functions of Java that were never meant to be run by external programs.

Last week, while announcing details of Sun's forthcoming Solaris 10 operating system, president Jonathan Schwartz noted that Java hasn't been afflicted by a single Java virus.

However, the new security hole could allow a virus to use the Java plug-in to invade PC systems. In October, a flaw in the Java plug-in for mobile phones raised the spectre that a malicious program disguised as a helpful application could attack a phone's software, if run by a user.

Like the recent IFRAME vulnerability in Microsoft's Internet Explorer, the Java flaw could allow a malicious Web site to download and execute a program that would compromise a visitor's PC.

"It could be easily used for spreading viruses or other malware," Pynnonen said in the email. "The exploit itself can't be easily embedded in email, because Java applets contained in email aren't normally started automatically. However an email message could contain a link to a Web page which has the exploit."

While Sun would not speculate on how the flaw could be used by attackers, the company did say that it worked hard to distribute the patch for it (which can be found here) to all users.

"We took this very seriously, and we have gone the extra mile to post these patches," a Sun representative said on Tuesday.

The advisories from Sun, Secunia and Pynnonen do not address whether the problem could affect Apple's Mac OS X operating system, which is based on a Unix-like core of code, similar to Linux. The Sun representative said that the Mac issue is being investigated.

Apple was not immediately available for comment.

CNET News.com's Stephen Shankland contributed to this report.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
44 out of 91 people found this useful


Full Talkback thread

0 comments


Related Jobs

Application Support Team Lead - Support Analyst - East Midlands

Application Support Team Lead - Support Analyst - East Midlands Leicestershire County Council is one of the top rated councils for service and ...

IBM Maximo Infrastructure Engineer

IBM Maximo Infrastructure Engineer Job ID GBS-0121292 Job type Full-time Regular Work country United Kingdom Posted 09-Jul-2008 Work city - Any Job ...

C# C# C# C#.NET DEVELOPER - FINANCE & BANKING - 60K + BONUS

C#.Net C#.Net C#.Net C#.Net C#.Net - ASSET MANAGEMENT One of Europes longest standing long/short Fund Managers is looking for a Senior C# Developer. ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment