ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Application development Toolkit

Critical Java flaws revealed

Published: 19 Sep 2002 12:36 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft released an advisory on Wednesday night warning all users of its Windows operating system of two new critical flaws that could allow a malicious attacker to take control of a victim's PC. The advisory can be found on Microsoft's Web site.

The critical flaws occur in the software giant's implementation of the Java Virtual Machine, which allows platform-independent programs to run on a PC.

"(The flaws) could enable an attacker to gain complete control over a user's system," stated the advisory. "This would enable the attacker to perform any operation that the user could, such as running applications; communicating with web sites; (and) adding, deleting or changing data."

An attacker could exploit the flaws by getting the victim to view a certain Web site with the code embedded in page. HTML email could also be a danger, unless the recipient uses Outlook 2002, Outlook Express 6.0 or has installed the Outlook Email Security Update. Finally, those who used the Internet Explorer security settings to disable Java applets won't be affected by the vulnerabilities.

The first vulnerability is caused by a lack of vigilance of certain Java classes that handle database requests. While the classes do attempt to block illegal requests, the security measures can be bypassed, the advisory states.

A second flaw occurs in a Java class that's provided to support the use of XML via Java, but allows all programs -- not just a select few -- to use the methods.

Microsoft has a patch posted on its site and linked from the advisory. Windows users can also get the patch through Windows Update.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
50 out of 77 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Service Desk Analyst @ top Hedge Fund! (ITIL,MS Office/Outlook)

Knowledge of Help Desk systems such as Touchpaper, Remedy AR System, Digital Workplace or Peregrine system would be beneficial, as would Microsoft ...

Technical Support Analyst- London- 23-27,000

Knowledge of Windows XP, MS Office 2003, Microsoft Internet Explorer, MS Outlook and MAC OS X. A leading media company based in the heart of London ...

IT Support/ Windows 2000/ XP/ Server2003/ AD/OFFCIE/ Outlook/KENT/25k

IT Desktop Support/ Windows 2000/ XP/ Server 2003/ Active Directory/ / Exchange/ OFFCIE/ Outlook Are you looking to further your career. Globally ...

Featured Talkback

The fact is: Software developers today are really designers and not coders. The reason that business anlaysts exist today to model solutions is because they understand the value of designing software before writing it. All too often developers create code that has little value because they do not understand that business classes interact with other classes within the confines of a working model or pattern.

By: 1000165269

Read full story:
Making sense of agile modelling