Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Security Vulnerabilities in Sun JRE may Allow an Untrusted Applet to Elevate its Privileges

 
Thread Tools Search this Thread
Old 02-08-2006, 11:33 PM   #1
Default Security Vulnerabilities in Sun JRE may Allow an Untrusted Applet to Elevate its Privileges


http://sunsolve.sun.com/search/docum...=1-26-102171-1

"Note: It is recommended that affected versions be removed from your system. For more
information, please see the installation notes on the respective java.sun.com download
pages."

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm




David H. Lipman
  Reply With Quote
Old 02-09-2006, 01:20 AM   #2
Virus Guy
 
Posts: n/a
Default Re: Security Vulnerabilities in Sun JRE may Allow an Untrusted Applet toElevate its Privileges
"David H. Lipman" wrote:

> http://sunsolve.sun.com/search/docum...=1-26-102171-1
>
> "Note: It is recommended that affected versions be removed from
> your system.


Well, which version is NOT affected?

I see that all these cases, that version 1.3.x is not affected.
Should I revert to that version?

How secure is version 1.5.0_05-b05 ?


Virus Guy
  Reply With Quote
Old 02-09-2006, 01:37 AM   #3
David H. Lipman
 
Posts: n/a
Default Re: Security Vulnerabilities in Sun JRE may Allow an Untrusted Applet to Elevate its Privileges
From: "Virus Guy" <>

| "David H. Lipman" wrote:
|
>> http://sunsolve.sun.com/search/docum...=1-26-102171-1
>>
>> "Note: It is recommended that affected versions be removed from
>> your system.

|
| Well, which version is NOT affected?
|
| I see that all these cases, that version 1.3.x is not affected.
| Should I revert to that version?
|
| How secure is version 1.5.0_05-b05 ?

Update to and use JRE 5 update 6.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm




David H. Lipman
  Reply With Quote
Old 02-09-2006, 04:10 AM   #4
Jim Byrd
 
Posts: n/a
Default Re: Security Vulnerabilities in Sun JRE may Allow an Untrusted Applet to Elevate its Privileges
Hi Virus Guy - I would strongly recommend against using ANY version prior to
1.5.0_05-b06. Contrary to the Sun Bulletin, a group of MVP's that have been
working on this issue for several months now have come to stongly suspect
that 1.3.x versions contain an exploit that is being utilized by
Winfixer/Vundo and have been recommending against the use of any earlier
version to include specifically the uninstalling of ALL prior versions. See
here: http://www.frsirt.com/english/advisories/2006/0467 and my Blog.


--
Regards, Jim Byrd, MS-MVP/DTS/AH-VSOP
My Blog, Defending Your Machine, here:
http://DefendingYourMachine.blogspot.com/



"Virus Guy" <> wrote in message news:
> "David H. Lipman" wrote:
>
>> http://sunsolve.sun.com/search/docum...=1-26-102171-1
>>
>> "Note: It is recommended that affected versions be removed from
>> your system.

>
> Well, which version is NOT affected?
>
> I see that all these cases, that version 1.3.x is not affected.
> Should I revert to that version?
>
> How secure is version 1.5.0_05-b05 ?





Jim Byrd
  Reply With Quote
Old 02-09-2006, 10:45 AM   #5
shawn
 
Posts: n/a
Default Re: Security Vulnerabilities in Sun JRE may Allow an Untrusted Applet to Elevate its Privileges
On Thu, 09 Feb 2006 01:37:05 GMT, "David H. Lipman"
<DLipman~nospam~@Verizon.Net> wrote:

>From: "Virus Guy" <>
>
>| "David H. Lipman" wrote:
>|
>>> http://sunsolve.sun.com/search/docum...=1-26-102171-1
>>>
>>> "Note: It is recommended that affected versions be removed from
>>> your system.

>|
>| Well, which version is NOT affected?
>|
>| I see that all these cases, that version 1.3.x is not affected.
>| Should I revert to that version?
>|
>| How secure is version 1.5.0_05-b05 ?
>
>Update to and use JRE 5 update 6.


And remove all of the other versions from your system.



shawn
  Reply With Quote
Old 02-09-2006, 11:45 AM   #6
SK
 
Posts: n/a
Default Re: Security Vulnerabilities in Sun JRE may Allow an Untrusted Applet to Elevate its Privileges
On Thu, 09 Feb 2006 05:45:01 -0500, shawn <>
wrote:

>On Thu, 09 Feb 2006 01:37:05 GMT, "David H. Lipman"
><DLipman~nospam~@Verizon.Net> wrote:
>
>>From: "Virus Guy" <>
>>
>>| "David H. Lipman" wrote:
>>|
>>>> http://sunsolve.sun.com/search/docum...=1-26-102171-1
>>>>
>>>> "Note: It is recommended that affected versions be removed from
>>>> your system.

>>|
>>| Well, which version is NOT affected?
>>|
>>| I see that all these cases, that version 1.3.x is not affected.
>>| Should I revert to that version?
>>|
>>| How secure is version 1.5.0_05-b05 ?
>>
>>Update to and use JRE 5 update 6.

>



Did that and removed all other version shown on Ad/remove programs.

However there is still a picture of "Java(TM) Control Panel" showing
on control panel. Its version seems to be 1.5.0 (build 1.5.0._06-b05
and its update info shows Dec 2005.

What is that and why does it not show any update info??


SK
  Reply With Quote
Old 02-09-2006, 02:27 PM   #7
Virus Guy
 
Posts: n/a
Default Re: Security Vulnerabilities in Sun JRE may Allow an Untrusted Applet toElevate its Privileges
Art wrote:

> I wonder why security conscious users have Java installed at all.
> I dropped it long ago and have never missed it. I know that some
> financial institutions require it


I'm running version 1.5.0_05-b05 and ever since I installed that
version (or perhaps a version or two before it) some page components
(presumably java graphics elements) have the annoying habbit of being
rendered/displayed in other windows that have the current focus (such
as word, excel, etc).

For example, on this page:

http:/www.forexdirectory.net/cad.html

The currency matrix above the chart is frequently drawn on-top of
portions of the screen where it shouldn't be (sometimes even on the
desktop). I don't know what that page would look like without Java...


Virus Guy
  Reply With Quote
Old 02-09-2006, 03:08 PM   #8
Jim Byrd
 
Posts: n/a
Default Re: Security Vulnerabilities in Sun JRE may Allow an Untrusted Applet to Elevate its Privileges
Hi Virus Guy - FWIW, that page renders correctly on my machine using IE6SP1
and 1.5.0_05-b06.

--
Regards, Jim Byrd, MS-MVP/DTS/AH-VSOP
My Blog, Defending Your Machine, here:
http://DefendingYourMachine.blogspot.com/



"Virus Guy" <> wrote in message news:
> Art wrote:
>
>> I wonder why security conscious users have Java installed at all.
>> I dropped it long ago and have never missed it. I know that some
>> financial institutions require it

>
> I'm running version 1.5.0_05-b05 and ever since I installed that
> version (or perhaps a version or two before it) some page components
> (presumably java graphics elements) have the annoying habbit of being
> rendered/displayed in other windows that have the current focus (such
> as word, excel, etc).
>
> For example, on this page:
>
> http:/www.forexdirectory.net/cad.html
>
> The currency matrix above the chart is frequently drawn on-top of
> portions of the screen where it shouldn't be (sometimes even on the
> desktop). I don't know what that page would look like without Java...





Jim Byrd
  Reply With Quote
Old 02-09-2006, 04:34 PM   #9
Gabriele Neukam
 
Posts: n/a
Default Re: Security Vulnerabilities in Sun JRE may Allow an Untrusted Applet to Elevate its Privileges
On that special day, Virus Guy, () said...

> http:/www.forexdirectory.net/cad.html
>
> The currency matrix above the chart is frequently drawn on-top of
> portions of the screen where it shouldn't be (sometimes even on the
> desktop). I don't know what that page would look like without Java...


rather empty. At least, if I refuse to let all these advertisment
cookies to be placed on my machine.


Gabriele Neukam




--
Ah, Information. A property, too valuable these days, to give it away,
just so, at no cost.


Gabriele Neukam
  Reply With Quote
Old 02-10-2006, 12:39 AM   #10
Stephen Howe
 
Posts: n/a
Default Re: Security Vulnerabilities in Sun JRE may Allow an Untrusted Applet to Elevate its Privileges
> However there is still a picture of "Java(TM) Control Panel" showing
> on control panel. Its version seems to be 1.5.0 (build 1.5.0._06-b05
> and its update info shows Dec 2005.


I had that. But on rebooting it was gone.

Stephen Howe




Stephen Howe
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Computer Security Information and What You Can Do To Keep Your SystemSafe! Ann.Anderson.group.com@gmail.com A+ Certification 0 12-06-2007 01:55 AM
Computer Security aldrich.chappel.com.use@gmail.com A+ Certification 0 11-27-2007 02:11 AM
Computer Security Information (Free Articles and eBooks) aditya.jaiswal.com.use@gmail.com DVD Video 0 10-10-2007 04:53 AM
Re: Missing WinXP Security Center Applet Steven L Umbach A+ Certification 2 06-27-2006 12:56 AM
Re: Missing WinXP Security Center Applet Steven L Umbach A+ Certification 0 06-22-2006 09:34 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46