|
|
>> Sun Java Runtime Environment Applets Handling Information Disclosure Vulnerabilities
|
Title : Sun Java Runtime Environment Applets Handling Information Disclosure Vulnerabilities VUPEN ID : VUPEN/ADV-2006-5075 CVE ID : CVE-2006-6736 - CVE-2006-6737
Rated as : Moderate Risk 
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-12-20
|
Two vulnerabilities have been identified in Sun Java Runtime Environment, which could be exploited by attackers to bypass security restrictions and disclose sensitive information. These issues are due to unspecified errors when handling certain applets, which could be exploited by malicious applets to access data in other applets.
Affected Products
Sun Java JDK 1.5.x (for Windows, Solaris, and Linux)
Sun Java JRE 1.3.x (for Windows, Solaris, and Linux)
Sun Java JRE 1.4.x (for Windows, Solaris, and Linux)
Sun Java JRE 1.5.x / 5.x (for Windows, Solaris, and Linux)
Sun Java SDK 1.3.x (for Windows, Solaris, and Linux)
Sun Java SDK 1.4.x (for Windows, Solaris, and Linux)
Solution
Upgrade to JDK/JRE 5.0 Upgrade 8, SDK/JRE 1.4.2_13, or SDK/JRE 1.3.1_19 :
http://www.java.com
References
http://www.vupen.com/english/advisories/2006/5075 http://sunsolve.sun.com/search/document.do?assetkey=1-26-102732-1
Credits
Vulnerabilities reported by Tom Hawtin
ChangeLog
2006-12-20 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|