main
Report a problem

Java flaw could lead to Windows, Linux attacks

JCAP   on 23 November 2004 - 22:34 · 33 comments & 4056 views

Advertisement (Why?)
A flaw in Sun Microsystems's plug-in for running Java on a variety of browsers and operating systems could allow a virus to spread through Microsoft Windows and Linux PCs. The vulnerability, found by Finnish security researcher Jouko Pynnonen in June, was patched last month by Sun Microsystems, but its details were not made public until Tuesday. Security information provider Secunia posted information about the flaw in an advisory that rated it a "highly critical" threat. The Java plug-in enables small Web programs, known as applets, to run safely on a user's computer. But the security flaw allows a malicious Web site accessed through a victim's browser to bypass those protections.

"It allows execution of attacker-supplied code without user interaction (apart from viewing a Web page) which usually means a "critical" classification," Pynonnen stated in an e-mail interview with CNET News.com. "The same exploit could also be used against various operating systems and browsers, which makes it more serious," he added. The vulnerability can be used to attack systems running on Windows or Linux, for example, and using major browser software such as Microsoft's Internet Explorer and Firefox--meaning a large number of systems are vulnerable to attack.

View: Full Story
News source: News.com

Post a comment · Send to friend Comments · There are 33 additional comments

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)