This application requires Javascript for optimal performance.

SUN.JavaWebStart.JNLP.Property.Tags.Unauthorized.Access

Release Date

Dec 20, 2005

Severity

critical

Impact

Security Bypass: Remote attackers can bypass security checking of vulnerable systems.

Description

This indicates an attempt to exploit a Security Bypass vulnerability in
Java Web Start.

The vulnerability is caused by an error when the vulnerable software handles
the "jnlp" file with a malicious property. It allows a remote attacker to bypass the java security policy by sending a crafted "jnlp" file.

Affected Products

Sun Java Web Start 1.2, Sun Java 2 Runtime Environment 1.4.2 _06 and runtime JAVA earlier versions.

Recommended Actions

Apply patch,available from the web site.

Sun Java 2 Runtime Environment 1.3 _05

Sun J2SE 5.0 (1.5.0) Update 2
http://java.sun.com/j2se/1.5.0/index.jsp

Sun J2SE 1.4.2
http://java.sun.com/j2se/1.4.2/download.html

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2005-0836

Reference/s

http://www.securityfocus.com/bid/12847 (BugTraq)

Reference: VID-11547