Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 14th, 2005, 11:24 AM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,180
Default Java Web Start / Sun JRE Sandbox Security Bypass Vulnerability

Quote:
Highly critical

Secunia
  #2  
Old June 14th, 2005, 12:03 PM
MikeBCda MikeBCda is offline
Very Frequent Poster
 
Join Date: Jan 2004
Location: southern Ont. Canada
Posts: 1,535
Default Re: Java Web Start / Sun JRE Sandbox Security Bypass Vulnerability

If I'm reading that right, it was fixed in JRE 1.5 (or 5.0, their numbering confuses me) Update 2, which has been available many months now.
__________________
Intel Atom D2700, 2 gig RAM, Win 7 x64 SP1 & IE-10, Firefox 21.0 (default). 320 gig HD, 6Mb DSL, Win firewall, Avast 8.0.1489 free, SpywareBlaster, MBAM
---
My name is Any Key. Please don't hit me.
  #3  
Old June 14th, 2005, 12:06 PM
GlobalForce's Avatar
GlobalForce GlobalForce is offline
Regular Poster
 
Join Date: Jun 2004
Location: Garden State, USA
Posts: 3,581
Thumbs up Re: Java Web Start / Sun JRE Sandbox Security Bypass Vulnerability

Good call Ron! I've alway's had suspicion's about unauthorized applet start's.

GF
__________________
"No matter what, no matter where ~ it's always home when love is there!"
  #4  
Old June 14th, 2005, 12:16 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,180
Default Re: Java Web Start / Sun JRE Sandbox Security Bypass Vulnerability

Quote:
Originally Posted by MikeBCda
If I'm reading that right, it was fixed in JRE 1.5 (or 5.0, their numbering confuses me) Update 2, which has been available many months now.

Their numbering system can get confusing. I'm using the 1.4.xxx versions.
  #5  
Old June 14th, 2005, 02:21 PM
diginsight's Avatar
diginsight diginsight is offline
Security Expert
 
Join Date: Feb 2002
Location: Netherlands
Posts: 228
Default Re: Java Web Start / Sun JRE Sandbox Security Bypass Vulnerability

I wonder why Sun keeps insisting pushing Java Web start with JRE, while I see no use for it and it has had it's load of vulnerabilities. The only way to remove the damn thing is by deleting the javaws folder.
  #6  
Old June 14th, 2005, 05:04 PM
snowieone
 
Posts: n/a
Default Re: Java Web Start / Sun JRE Sandbox Security Bypass Vulnerability

THIS ISSUE WAS FIXED BUT IF YOU DISLIKE WEBSTART JUST>

To work around the described issue, disable Java Web Start applications from being launched from a web browser as follows:

For Internet Explorer:

Right click on the "Start" button and select "Explore"
In the "Start Menu" window, select "Tools" => "Folder Options"
From the "Folder Options" window, select the "File Types" tab
From the "Registered File Types" window, scroll down and locate the "JNLP - JNLP File"
Select the "JNLP - JNLP File" and click the "Delete" button
For Mozilla:

Select "Preferences" under the browser's "Edit" menu
In the "Preferences" window, select "Helper Applications" located under the "Navigator" category
Under "Files types", scroll down and locate "application/x-java-jnlp-file"
Select "application/x-java-jnlp-file" and click the "Remove" button
Notes:

1. On Microsoft Windows, applications may also be launched from the desktop icon or Start Menu if a shortcut was previously created for an application. Unknown applications should not be launched through the desktop icon or the Start Menu. Shortcuts can be removed by using the Java Web Start Application Manager through the "Application/Remove Shortcut" menu item.
  #7  
Old June 14th, 2005, 06:12 PM
diginsight's Avatar
diginsight diginsight is offline
Security Expert
 
Join Date: Feb 2002
Location: Netherlands
Posts: 228
Default Re: Java Web Start / Sun JRE Sandbox Security Bypass Vulnerability

Hi snowieone,

Thanks for this solution. It's much more elegant and scriptable than just deleting the entire javaws folder. I already discoverd how to remove the desktop icon using an installation script.

Now I still have to verify it doesn't recreate these keys after updating JRE.
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:09 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums