Java vulnerability details released

Patch now available for GIF processing issue.

A flaw in the GIF processing procedures of Sun Microsystems' Java Virtual Machine, which could allow code to break out of the Java sandbox, has been reported and a patch released.

Advertise on www.virusbtn.com

The flaw, which could allow remote execute of code on a victim machine if exploited accurately, was first discovered over six months ago, and reported to TippingPoint's Zero Day Initiative (ZDI) by an anonymous researcher. The release of details of the flaw follows a patch release from Sun.

The issue is thought to affect several versions of the Java Runtime Environment software, on multiple platforms. The latest version of the software is thought to be already safe from the flaw, users of older versions (version 5 update 9 and earlier) are advised to apply updates as soon as possible. The alert from ZDI is here, with Sun's announcement and links to fixes here.

19 January 2007

Tags:    del.icio.us  digg this! digg this


Poll

Do you use the same password(s) across multiple websites?
I use the same password for all sites
I have a number of passwords but use the same for some sites
I use a different password for each site
I don't sign up to any sites that require a password

Leave a comment
View 4 comments

Jobs Recruit Sidebar

VB100 certification

VB100 This month VB's test team put 26 products to the test on Windows Server 2008. John Hawes has the full results.
See full results.

Virus Bulletin currently has 191,005 registered users.