Advertisement
Promo

Security threats Toolkit

Sun to issue mobile Java fix

David Meyer ZDNet.co.uk

Published: 15 Aug 2008 15:57 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Sun is to ship a fix for vulnerabilities that were found in the mobile version of Java by a Polish security researcher.

The flaws are only present in older versions of Java 2 Platform Micro Edition (J2ME) that were current around 2004, according to the company. Friday's announcement follows the report by Adam Gowdiak, founder and chief executive of Security Explorations, claiming that he had found serious vulnerabilities in implementations of mobile Java, particularly on Nokia Series 40 handsets.

The vulnerabilities would allow someone to hack into a Series 40 handset and control voice and data functionality among other things, according to Gowdiak.

Gowdiak had demanded €20,000 (£16,000) from Sun or Nokia for the full details of the vulnerabilities that he said he had found. It is not known whether either company paid up, as neither has commented on that issue. Sun told ZDNet.co.uk on Friday that Gowdiak had contacted the company on 7 August, prior to going public with his findings. Sun then "researched the situation" and confirmed "a couple potential vulnerabilities" that were specific to J2ME, a spokesperson said.

Read this

 PSCS3
Photos: Computer blunders of the technologically inept

Over eight years as a PC technician, Rod Shelley documented all manner of operator-induced hardware misfortunes...

Read more +

According to Sun, most of the "security explorations" carried out by Gowdiak were specific to the Nokia phone stack's implementation of J2ME, rather than J2ME itself. Nokia said on Tuesday that it was currently testing Gowdiak's claims.

"Sun can confirm that there are a couple of potential vulnerabilities outlined in [Gowdiak's] post that are specific to [J2ME] but those are limited to older versions of [J2ME]," Sun's spokesperson said. "In addition, these vulnerabilities would be extremely difficult to exploit because they would require device-specific information that is not readily available."

Sun's spokesperson stressed that the current version of the J2ME implementation, CLDC-HI, is not affected by the vulnerabilities. Licensees of the affected versions have been notified by Sun and will receive a fix within the next month or two, the spokesperson added.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment

Watchdog reveals illegal sale of phone...

The Information Commissioner's Office is preparing a prosecution file against a mobile operator's employees who allegedly sold on thousands of customers' details to a competitor. The... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters