>> Sun Java Runtime Environment Network Access Restrictions Bypass Vulnerability
Title : Sun Java Runtime Environment Network Access Restrictions Bypass Vulnerability VUPEN ID : VUPEN/ADV-2007-2573 CVE ID : CVE-2007-3922
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-07-19
Technical Description
A vulnerability has been identified in Sun JDK, JRE and SDK, which could be exploited by attackers to bypass security restrictions. This issue is caused by an unspecified error in the Applet Class Loader when processing applets, which could allow an untrusted applet that is loaded from a remote system to circumvent network access restrictions and establish socket connections to certain services running on the vulnerale host, as if it were loaded from the system that the applet is running on, which may allow the untrusted remote applet the ability to exploit any security vulnerabilities existing in the services it has connected to.