Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 4th, 2002, 09:45 PM
javacool javacool is offline
BrightFort Moderator
 
Join Date: Feb 2002
Posts: 3,880
Default MS Security Bulletin MS02-13

Java Applet Can Redirect Browser Traffic

http://www.microsoft.com/technet/sec...013.asp.<br />

__________________

*Official BrightFort Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #2  
Old March 4th, 2002, 09:47 PM
javacool javacool is offline
BrightFort Moderator
 
Join Date: Feb 2002
Posts: 3,880
Default Re: MS Security Bulletin MS02-13

Quote:
Microsoft Security Bulletin MS02-013


Java Applet Can Redirect Browser Traffic
Originally posted: March 04, 2002

Summary
Who should read this bulletin: Customers using Microsoft® Internet Explorer® in a configuration where a proxy server is interposed between the browser and the Internet.

Impact of vulnerability: Information Disclosure

Maximum Severity Rating: Critical

Recommendation: Customers using IE in a proxy server configuration as indicated above should immediately apply the patch.

Affected Software: Versions of the Microsoft virtual machine (Microsoft VM) are identified by build numbers, which can be determined using the JVIEW tool as discussed in the FAQ. The following builds of the Microsoft VM are affected:

All builds of the Microsoft VM up to and including build 3802.
__________________

*Official BrightFort Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #3  
Old March 4th, 2002, 09:47 PM
javacool javacool is offline
BrightFort Moderator
 
Join Date: Feb 2002
Posts: 3,880
Default Re: MS Security Bulletin MS02-13

Patch availability
Download locations for this patch
Upgrade to Microsoft VM build 3805 or later at http://www.microsoft.com/java/vm/dl_vm40.htm
__________________

*Official BrightFort Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #4  
Old March 4th, 2002, 11:21 PM
UNICRON's Avatar
UNICRON UNICRON is offline
Technical Expert
 
Join Date: Feb 2002
Location: Nanaimo BC Canada
Posts: 1,935
Default Re: MS Security Bulletin MS02-13

no win2k patch?
__________________
Not every thing that can be counted counts, and not everything that counts can be counted.
  #5  
Old March 4th, 2002, 11:44 PM
FanJ
 
Posts: n/a
Default Re: MS Security Bulletin MS02-13

As I read it on the download page:
A Windows 2000 hotfix including Microsoft VM build 3805 will be available soon.
  #6  
Old March 5th, 2002, 07:53 AM
Checkout's Avatar
Checkout Checkout is offline
Security Rhinoceros
 
Join Date: Feb 2002
Posts: 1,226
Default Re: MS Security Bulletin MS02-13

Quote:
As I read it on the download page:
A Windows 2000 hotfix including Microsoft VM build 3805 will be available soon.
I'm dreading All Fools' Day! *How on Earth will we be able to tell the real M$ bug reports from the fakes? *
__________________
My Novel
  #7  
Old March 5th, 2002, 04:33 PM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re: MS Security Bulletin MS02-13

Quote:
no win2k patch?

Available in the meanwhile (XP as well) using one and the same link:

www.microsoft.com/java/vm/dl_vm40.htm

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #8  
Old March 5th, 2002, 05:31 PM
wizard's Avatar
wizard wizard is offline
Frequent Poster
 
Join Date: Feb 2002
Location: Europe - Germany - Duesseldorf
Posts: 818
Default Re: MS Security Bulletin MS02-13

Another alternativ to be protected from this security hole is to use the original Java Runtime Engine from Sun. It's free and can be downloaded from

http://java.sun.com/j2se/1.3/jre/download-windows.html#software

wizard
__________________
wizardRESEARCH - Malware Research & Analysis since 1989
  #9  
Old March 5th, 2002, 06:58 PM
javacool javacool is offline
BrightFort Moderator
 
Join Date: Feb 2002
Posts: 3,880
Default Re: MS Security Bulletin MS02-13

More links on this vulnerability:

http://www.theregister.co.uk/content/55/24295.html

http://www.xs4all.nl/~harmwal/issue/wal-01.txt

http://home.netscape.com/security/
__________________

*Official BrightFort Website*
*SpywareBlaster*

*Please note: I am not responsible if any advice herein causes any trouble whatsoever *
  #10  
Old March 6th, 2002, 01:22 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re: MS Security Bulletin MS02-13

The advice from wizard is IMHO a very solid one:

Quote:
Another alternativ to be protected from this security hole is to use the original Java Runtime Engine from Sun.

There's a new version available as well: v1.4:

http://java.sun.com/j2se/1.4/download.html

regards.

paul

__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #11  
Old March 6th, 2002, 11:05 AM
spy1's Avatar
spy1 spy1 is offline
Massive Poster
 
Join Date: Dec 2002
Location: Clover, SC
Posts: 3,130
Default Re: MS Security Bulletin MS02-13

Exactly (step-by-step) how would one go about changing from VM to Sun? What do you do? Pete
__________________
"When fascism comes to America it will come wrapped in the flag and carrying a cross." Sinclair Lewis
  #12  
Old March 6th, 2002, 03:01 PM
FanJ
 
Posts: n/a
Default Re: MS Security Bulletin MS02-13

Quote:
Exactly (step-by-step) how would one go about changing from VM to Sun? What do you do? Pete

Good question, Pete!

Quote from this site:
http://www.microsoft.com/java/vm/dl_vm40.htm

Quote:
WARNING: Please note that once you have installed the updated Microsoft VM it cannot be uninstalled.
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:08 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums