Note: This is an archival copy of Security Sun Alert 200034 as previously published on http://sunsolve.sun.com.
Latest version of this security advisory is available from http://support.oracle.com as Sun Alert 1000029.1.
Article ID : 1000029.1
Article Type : Sun Alerts (SURE)
Last reviewed : 2010-01-19
Audience : PUBLIC
Copyright Notice: Copyright © 2010, Oracle Corporation and/or its affiliates.

An Untrusted Applet may Access Restricted Resources



Category
Security

Release Phase
Resolved

Bug Id
4483397, 4618676, 4738457

Date of Resolved Release
06-JUN-2003

A vulnerability in the Java Runtime Environment

1. Impact

A vulnerability in the Java Runtime Environment may allow an untrusted applet to:

  1. access restricted resources
  2. access to HTTP request properties
  3. access user authentication information with Java Plug-in

Sun acknowledges with thanks, Harmen van der Wal, for bringing these issues to our attention.


2. Contributing Factors

These issues can occur in the following releases:

1. Access to restricted resources:

Windows Production Releases

  • SDK and JRE 1.3.1_02 or earlier
  • SDK and JRE 1.3.0_05 or earlier
  • SDK and JRE 1.2.2_010 or earlier
  • JDK 1.1.8_008 or earlier

Solaris Operating Environment (OE) Reference Releases

  • SDK and JRE 1.2.2_010 or earlier
  • JDK 1.1.8_008 or earlier

Solaris OE Production Releases

  • SDK and JRE 1.3.1_02 or earlier
  • SDK and JRE 1.3.0_05 or earlier
  • SDK and JRE 1.2.2_10 or earlier
  • JDK 1.1.8_14 or earlier

Linux Production Releases

  • SDK and JRE 1.3.1_02 or earlier
  • SDK and JRE 1.3.0_05 or earlier
  • SDK and JRE 1.2.2_010 or earlier

Note: SDK and JRE 1.4.0 and later releases for Windows, Linux, and Solaris are not affected

2. Access to HTTP request properties:

Windows Production Releases

  • SDK and JRE 1.3.1_02 or earlier
  • SDK and JRE 1.3.0_05 or earlier
  • SDK and JRE 1.2.2_011 or earlier
  • JDK 1.1.8_008 or earlier

Solaris Operating Environment (OE) Reference Releases

  • SDK and JRE 1.2.2_011 or earlier
  • JDK 1.1.8_008 or earlier

Solaris OE Production Releases

  • SDK and JRE 1.3.1_02 or earlier
  • SDK and JRE 1.3.0_05 or earlier
  • SDK and JRE 1.2.2_11 or earlier
  • JDK 1.1.8_14 or earlier

Linux Production Releases

  • SDK and JRE 1.3.1_02 or earlier
  • SDK and JRE 1.3.0_05 or earlier
  • SDK and JRE 1.2.2_011 or earlier

Note: SDK and JRE 1.4.0 and later releases for Windows, Linux, and Solaris are not affected.

3. Access to user authentication information:

Windows Production Releases

  • SDK and JRE 1.4.1_01 or earlier
  • SDK and JRE 1.4.0_03 or earlier
  • SDK and JRE 1.3.1_06 or earlier
  • SDK and JRE 1.2.2_014 or earlier

Solaris Operating Environment (OE) Reference Releases

  • SDK and JRE 1.2.2_014 or earlier

Solaris OE Production Releases

  • SDK and JRE 1.4.1_01 or earlier
  • SDK and JRE 1.4.0_03 or earlier
  • SDK and JRE 1.3.1_06 or earlier
  • SDK and JRE 1.2.2_14 or earlier

Linux Production Releases

  • SDK and JRE 1.4.1_01 or earlier
  • SDK and JRE 1.4.0_03 or earlier
  • SDK and JRE 1.3.1_06 or earlier
  • SDK and JRE 1.2.2_014 or earlier

3. Symptoms

There are no reliable symptoms that would show the described issues have been exploited.


4. Workaround

There is no workaround. Please see the "Resolution" section below.


5. Resolution

These issues are addressed in the following releases:

1. Access to restricted resources:

Windows Production Releases

  • SDK and JRE 1.3.1_03 and later
  • SDK and JRE 1.2.2_011 and later
  • JDK 1.1.8_009 and later

Solaris Operating Environment (OE) Reference Releases

  • SDK and JRE 1.2.2_011 and later
  • JDK 1.1.8_009 and later

Solaris OE Production Releases

  • SDK and JRE 1.3.1_03 and later
  • SDK and JRE 1.2.2_11 and later
  • JDK 1.1.8_15 and later

Linux Production Releases

  • SDK and JRE 1.3.1_03 and later
  • SDK and JRE 1.2.2_011 and later

2. Access to HTTP request properties:

Windows Production Releases

  • SDK and JRE 1.3.1_03 and later
  • SDK and JRE 1.2.2_012 and later
  • JDK 1.1.8_009 and later

Solaris Operating Environment (OE) Reference Releases

  • SDK and JRE 1.2.2_012 and later
  • JDK 1.1.8_009 and later

Solaris OE Production Releases

  • SDK and JRE 1.3.1_03 and later
  • SDK and JRE 1.2.2_12 and later
  • JDK 1.1.8_15 and later

Linux Production Releases

  • SDK and JRE 1.3.1_03 and later
  • SDK and JRE 1.2.2_012 and later

3. Access to user authentication information:

Windows Production Releases

  • SDK and JRE 1.4.1_02 and later
  • SDK and JRE 1.4.0_04 and later
  • SDK and JRE 1.3.1_07 and later
  • SDK and JRE 1.2.2_015 and later

Solaris Operating Environment (OE) Reference Releases

  • SDK and JRE 1.2.2_015 and later

Solaris OE Production Releases

  • SDK and JRE 1.4.1_02 and later
  • SDK and JRE 1.4.0_04 and later
  • SDK and JRE 1.3.1_07 and later

Note: Users of 1.2.2 releases should upgrade to a later release.

Linux Production Releases

  • SDK and JRE 1.4.1_02 and later
  • SDK and JRE 1.4.0_04 and later
  • SDK and JRE 1.3.1_07 and later
  • SDK and JRE 1.2.2_015 and later

SDK and JRE releases are available at:

	http://java.sun.com/j2se/

This Sun Alert notification is being provided to you on an "AS IS" basis. This Sun Alert notification may contain information provided by third parties. The issues described in this Sun Alert notification may or may not impact your system(s). Sun makes no representations, warranties, or guarantees as to the information contained herein. ANY AND ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT, ARE HEREBY DISCLAIMED. BY ACCESSING THIS DOCUMENT YOU ACKNOWLEDGE THAT SUN SHALL IN NO EVENT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES THAT ARISE OUT OF YOUR USE OR FAILURE TO USE THE INFORMATION CONTAINED HEREIN. This Sun Alert notification contains Sun proprietary and confidential information. It is being provided to you pursuant to the provisions of your agreement to purchase services from Sun, or, if you do not have such an agreement, the Sun.com Terms of Use. This Sun Alert notification may only be used for the purposes contemplated by these agreements.

Copyright 2000-2010 Sun Microsystems, Inc., 4150 Network Circle, Santa Clara, CA 95054 U.S.A. All rights reserved.


Product
Sun Java System Web Server






















Attachments
This solution has no attachment