AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
December 03, 2008, 02:56:59 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4763 Members
Latest Member: WIassipsyKimb
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Topic: Apple Security Update Fixes Multiple Java Platform Vulnerabilities 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Apple Security Update Fixes Multiple Java Platform Vulnerabilities  (Read 760 times)
TJ
Tech Team
Hero Member
********
Offline Offline

Posts: 136



View Profile
Apple Security Update Fixes Multiple Java Platform Vulnerabilities
« on: September 17, 2005, 10:43:34 AM »

* Technical Description *

Multiple vulnerabilities were identified in Java on Apple Mac OS X, which could be exploited by remote or local attackers to bypass certain security restrictions, disclose sensitive information, or gain elevated privileges.

The first issue is due to a race condition when handling a temporary directory, which could be exploited by local attackers to corrupt or create arbitrary files.

The second flaw is due to a race condition in the privileged helper that creates temporary files insecurely when updating Java shared archives, which could be exploited by local attackers to corrupt or create arbitrary files.

The third vulnerability is due to an unspecified error when launching the utility used to update Java shared archives, which could be exploited by malicious users to execute arbitrary commands with elevated privileges.

The fourth issue is due to an unspecified error when handling specially crafted applets, which may be exploited by malicious web sites to bypass the default security policy and read/write arbitrary files on a vulnerable system with the privileges of the user running the untrusted applet.

The fifth flaw is due to an error where it is possible for the same port to be opened as a Java ServerSocket multiple times, which could allow a Java program to intercept data intended for the ServerSocket of a different Java program.

 * Affected Products *

Mac OS X 10.4.2
Mac OS X 10.3.9

 * Solution *

Upgrade to Java version 1.4.2_09 or 1.3.1_16 :
http://www.apple.com/support/downloads/

 * References *

http://www.frsirt.com/english/advisories/2005/1734
http://docs.info.apple.com/article.html?artnum=302266
http://docs.info.apple.com/article.html?artnum=302265
Logged
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Topic: Apple Security Update Fixes Multiple Java Platform Vulnerabilities « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!