Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 16th, 2007, 10:17 AM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,180
Default Sun JRE Font Parsing Vulnerability

Quote:
Secunia Advisory: SA26402
Release Date: 2007-08-16

Critical:
Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

Software: Sun Java JDK 1.5.x
Sun Java JRE 1.4.x
Sun Java JRE 1.5.x / 5.x
Sun Java SDK 1.4.x
Secunia
  #2  
Old August 16th, 2007, 02:56 PM
attila4000's Avatar
attila4000 attila4000 is offline
Regular Poster
 
Join Date: Feb 2005
Location: Rahway, NJ, USA
Posts: 51
Lightbulb Re: Sun JRE Font Parsing Vulnerability

thats why i uninstalled both Sun Java JRE and adobe reader from my pc. its two less vulnerabilities to worry about for me. its bad enough that i have to keep patching ms windows and office.
__________________
Attila4000


Security Setup: WinXP Pro (2 Limited User Accounts) / Avira AntiVir Personal 8.0 / Actiontec Firewall + NAT / Windows XP Pro Firewall
Computer: Dell xps 600 / Intel pentium D 2.80ghz / 2 gb sdram
ISP: Verizon Online DSL (1.5 mb/384 kb)
Location: Rahway, NJ, USA
  #3  
Old August 16th, 2007, 07:06 PM
ccsito's Avatar
ccsito ccsito is offline
Very Frequent Poster
 
Join Date: Jul 2006
Location: Nation's Capital
Posts: 1,579
Default Re: Sun JRE Font Parsing Vulnerability

This looks worse than the Vundo/Virtumonde trojan that used a flaw in the early versions of Java 1.4 to inject the adware into a PC.

Some websites were designed to run Java applets so if you needed to log into those websites, you had no choice but to install it (or else not use the system).
  #4  
Old August 17th, 2007, 01:32 AM
TOMxEU's Avatar
TOMxEU TOMxEU is offline
Very Frequent Poster
 
Join Date: Oct 2005
Location: Slovakia
Posts: 1,530
Default Re: Sun JRE Font Parsing Vulnerability

This is a good reason to keep JRE allways updated, because they reveal vulnerabilities in old versions as soon as the new one (patched one) is out.
__________________
Real-Time: Nothing | On-Demand: Nothing [ Lenovo E525 | CCleaner | Chrome | KC SUMo | WiseCare 365 ] ( BlackViper / DEP / OpenDNS / UAC / WiFiRouter )
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:33 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums