main

Vulnerability hits Java for cell phones

malebolgia   on 24 October 2004 - 00:47 · 4 comments & 1173 views

Advertisement (Why?)
A Polish researcher has found two vulnerabilities in the cell phone version of Sun Microsystems' Java software that under unusual circumstances could let a malicious program read private information or render a phone unusable.

The flaws are difficult to exploit because malicious programs must be tailored to a specific model of cell phone, said Adam Gowdiak, a 29-year-old security researcher with the Poznan Supercomputing and Networking Center who discovered the vulnerabilities. He figured out how to attack a Nokia 6310i mobile phone, but the effort took four months, he said in a Friday posting to the BugTraq vulnerability mailing list.

Before the vulnerabilities could be exploited, a phone user would have to download and run a malicious Java program, called a midlet, Gowdiak said in an e-mail interview. He's not aware of a way to automate an attack. He notified Sun of the vulnerabilities in August, and the company said it sent Java licensees a patched version of the vulnerable component, called the Java bytecode verifier, within two weeks. "We have not seen any attempts to exploit this vulnerability, but if there is one, the user can simply delete...the applications they downloaded from an untrusted source," said Eric Chu, Sun's director of marketing for the Java 2 Micro Edition, or J2ME, software.

News source: ZDNet.com


Thanks to Morgan and Carlo for the heads-up on this one!

Post a comment · Send to friend Comments · There are 4 additional comments
(1 reply) #1 nikvasilev on 24 Oct 2004 - 01:24
That is why people should use microsoft based smartphones like mpx200.
#1.1 nookadum on 24 Oct 2004 - 11:47
Which even has MORE security holes than a Symbian/Linux phone. I should know, I have an SPV Tanager.
#2 macster on 24 Oct 2004 - 08:52
Are you serious?
#3 E2icj on 24 Oct 2004 - 15:05
Anyone find out how much he was paid? (How much DO you get paid for finding security holes?) and (Jesus..4 months?) -also- whats an SPV Tanager? (I could just google it, but I think I'll be alot easier to understand if someone else explains it to me.)

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)