LWN.net Logo

sun-jdk: applet privilege escalation

Package(s):sun-jdk sun-jre blackdown-jdk CVE #(s):CVE-2005-3905 CVE-2005-3906
Created:January 16, 2006 Updated:January 18, 2006
Description: Adam Gowdiak discovered multiple vulnerabilities in the Java Runtime Environment's Reflection APIs that may allow untrusted applets to elevate privileges. A remote attacker could embed a malicious Java applet in a web page and entice a victim to view it. This applet can then bypass security restrictions and execute any command or access any file with the rights of the user running the web browser.
Alerts:
Gentoo 200601-10 2006-01-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds