10 Apr 2010
Security researchers have warned of a flaw in Java that could allow malware writers to inject code onto user's machines.
The flaw is in the Java Web Start system built for developers, and affects every version since Java 6 Update 10.
The code contains a NPAPI plug-in and ActiveX control called Java Deployment Toolkit which does not check the full parameters of URLs.
"The toolkit provides only minimal validation of the URL parameter, allowing us to pass arbitrary parameters to the [Java Web Start] utility, which provides enough functionality via command line arguments to allow this error to be exploited," wrote researcher Tavis Ormandy on the Full Disclosure mailing list.
"The simplicity with which this error can be discovered has convinced me that releasing this document is in the best interest of everyone except the vendor."
Ormandy explained that the flaw leaves all Windows users of Java open to attack. He published his findings because Sun Microsystems owner Oracle does not consider the bug important enough to break its quarterly patching schedule.
"Sun has been informed about this vulnerability, however, they informed me they do not consider this vulnerability to be of high enough priority to break their quarterly patch cycle," he said.
"For various reasons, I explained that I did not agree, and intended to publish advice to temporarily disable the affected control until a solution is available."
Latest stories from Open Source
Related videos
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Lead PHP Developer - Technical Architect - Ecommerce...
C# Software Engineers required to join rapidly expanding...
Java / J2EE Software Engineers required to join rapidly...
Developer (MIS / Business Systems - SQL / T-SQL, HTML...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Well now we know where Ellison stands on JAVA
Otherwise they would be working on an out of band patch for this run code vulnerability.
Posted by: FDunn 05 Jul 2010