Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Java Bug Makes IE, Firefox Vulnerable ("Highly Critical" - Update Required)
TechWeb ^ | November 23, 2004 | TechWeb News

Posted on 11/23/2004 11:39:35 PM PST by Eagle9

A flaw in Sun's Java Virtual Machine can open up the two most popular browsers, Microsoft's Internet Explorer and Mozilla's Firefox, to attack, security researchers said Tuesday.

According to Reston, Vir.-based iDefense and Danish security vendor Secunia, the bug in Java 2 Runtime Environment (JRE), Standard Edition could let attackers bypass the Java security "sandbox" and all security restrictions within Java applets on Web sites.

JRE is the plug-in software that establishes a connection between the browser and the Java platform, and makes it possible for Web browsers to run Java applets stashed on Web sites.

Hackers using the exploit could essentially can complete control of the compromised computer, said iDefense, letting them "access, download, upload, or execute files as well as access the network."

iDefense confirmed that the vulnerability exists on J2SE 1.4.2_01 and 1.4.2_04, and may also be within earlier versions as well.

Because the bug exists in Java, it's not limited to one browser. "Various browsers such as Internet Explorer, Mozilla, and Firefox on both Windows and Unix platforms can be exploited if they are running a vulnerable Java Virtual Machine," said iDefense in its online advisory.

Finnish researcher Juoko Pynnonen, who first spotted the vulnerability, noted that although his test exploit wouldn't work on Opera Software's Opera browser -- it uses a slightly different method to connect to JavaScript and Java -- it still may be vulnerable to a variation of the exploit.

Pynnonen brought the problem to Sun's attention in late April, 2004, but Sun has only now posted an update -- J2SE 1.4.2_06 -- on its Web site.

Secunia rated the vulnerability as "Highly critical," and urged users to update Java 2 immediately.
______________________________________________________

Source: Download Java 2 Platform, Standard Edition, v 1.4.2 (J2SE)

J2SE 1.4.2

Download Java 2 Platform, Standard Edition, v 1.4.2 (J2SE)
 

API Specifications
Documentation
White Papers
Compatibility

 
Bug Database

Forums
 

Tutorials & Code Camps
Online Sessions & Courses
Instructor-Led Courses
Course Certification
 
 

Java 2 Standard Edition, version 1.4.2 section

Japanese
NetBeans IDE + J2SE SDK

J2EE 1.4
*
netbeans logo
This distribution of the J2SE Software Development Kit (SDK) includes NetBeans IDE, which is a powerful integrated development environment for developing applications on the Java platform. More info...

Download J2SE v 1.4.2_04 SDK with NetBeans 3.6 Bundle
*
*
download J2EE
The Java 2 Enterprise Edition 1.4 SDK adds support for EJBs, JSPs, XML, and Web Services APIs in a single bundle. More info...


Download J2EE 1.4 SDK

*
  J2SE v 1.4.2_06  SDK  includes the JVM technology

The J2SE Software Development Kit (SDK) supports creating J2SE applications. More info...
Download J2SE SDK
Installation Instructions  

ReadMe   ReleaseNotes  
Sun License   Third Party Licenses

  J2SE v 1.4.2_06  JRE  includes the JVM technology
The J2SE Java Runtime Environment (JRE) allows end-users to run Java applications. More info...

Download J2SE JRE

Installation Instructions   ReadMe   ReleaseNotes  
Sun License   Third Party Licenses

* J2SE v 1.4.2 Documentation  

 
* J2SE 1.4.2 Documentation
Download

View

*
* Installation Instructions for Documentation

View J2SE 1.4.2 Installation Instruction
*
* License View J2SE 1.4.2 Document License
       

* Solaris OS Patches Solaris SPARC Solaris x86
* Patches Download Solaris SPARC Patches Download Solaris Intel Patches

       
* Other Downloads    
*
* Java Cryptography Extension (JCE)
Unlimited Strength Jurisdiction Policy Files 1.4.2
Download


Supported System Configurations

Get J2SE on DVD or CD

Confused or having trouble downloading or installing?
See the download help.



TOPICS: Culture/Society; Technical
KEYWORDS: computers; firefox; ie; internet; internetexploiter; java; microsoft; technical
Navigation: use the links below to view more comments.
first 1-2021-4041-52 next last

1 posted on 11/23/2004 11:39:35 PM PST by Eagle9
[ Post Reply | Private Reply | View Replies]

To: Eagle9
To everyone: Don't try to download the bad version (which may be the one listed above). Go to java.com and download Java version 1.5 under the Free Download area in green.

This is the latest version and it has many enhancements for speed for newly-written code.
2 posted on 11/23/2004 11:43:50 PM PST by ScottM1968
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach; backhoe

I hate to post and run, but I'm in dire need of sleep.


3 posted on 11/23/2004 11:44:43 PM PST by Eagle9
[ Post Reply | Private Reply | To 1 | View Replies]

To: ScottM1968

At the Sun link, the verion is 1.4.2.06
At the Java.com link, the version is 1.4.2.05


4 posted on 11/23/2004 11:55:18 PM PST by TomGuy (America: Best friend or worst enemy. Choose wisely.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: TomGuy

Sorry about that. You will need to go under the Developer's tab to get 1.5.0. That tab area is purple.

Look for J2SE 5.0. On the right hand side under "Popular Downloads" is the J2SE 5.0 download area. Once there choose the "J2SE 5.0 JRE" (which is the latest Java Runtime Environment).

That address, if you want to go right there, is as follows:

http://java.sun.com/j2se/1.5.0/download.jsp


5 posted on 11/24/2004 12:00:43 AM PST by ScottM1968
[ Post Reply | Private Reply | To 4 | View Replies]

To: ScottM1968

I've already installed it and uninstalled all my previous JRE's.


6 posted on 11/24/2004 12:05:52 AM PST by goldstategop (In Memory Of A Dearly Beloved Friend Who Lives On In My Heart Forever)
[ Post Reply | Private Reply | To 5 | View Replies]

To: ScottM1968

Thanks for the update. I'm developing in Java and it's important to know of sandbox vulnerabilities.


7 posted on 11/24/2004 12:06:34 AM PST by FastCoyote
[ Post Reply | Private Reply | To 5 | View Replies]

To: Eagle9

tag. And I just installed firefox, too!


8 posted on 11/24/2004 12:12:30 AM PST by flashbunny (Every thought that enters my head requires its own vanity thread.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

PING -- FYI


9 posted on 11/24/2004 12:13:48 AM PST by Boomer Geezer (Sgt. Wanda Dabbs, 22, of the 230th, called out, "That's my president, hooah!" and there were cheers.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: goldstategop
So let me get this straight ... download the new version, uninstall any previous version of JAVA I have on the system, and then install the new one, right?

The new install won't overlay the old one? Or is it just safer to uninstall the old and install the new?

10 posted on 11/24/2004 12:17:53 AM PST by Boomer Geezer (Sgt. Wanda Dabbs, 22, of the 230th, called out, "That's my president, hooah!" and there were cheers.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Eagle9

Esay link for this quick and easy Java 2 downlaod--->>

http://java.com/en/download


11 posted on 11/24/2004 12:19:55 AM PST by dennisw (G_D: Against Amelek for all generations)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dennisw

That is a link that will let you download the previous bad 1.4.2. The newer 1.4.2 is listed above (version 6, I think) and the best version is 1.5.0 also listed above in the developer's section.


12 posted on 11/24/2004 12:31:15 AM PST by ScottM1968
[ Post Reply | Private Reply | To 11 | View Replies]

To: ScottM1968

Holy cow. I screwed that up?


13 posted on 11/24/2004 12:31:56 AM PST by dennisw (G_D: Against Amelek for all generations)
[ Post Reply | Private Reply | To 12 | View Replies]

To: dennisw

Hey, don't worry. I expected it the "Free Download" link to give the new 1.5.0 I've had for several months.

We were both wrong and Sun hasn't updated its own link.


14 posted on 11/24/2004 12:35:42 AM PST by ScottM1968
[ Post Reply | Private Reply | To 13 | View Replies]

To: dennisw; Eagle9; ScottM1968; TomGuy

When Y'all decide what one we REALLY need please make the link in large bold print, Thanks


15 posted on 11/24/2004 12:37:29 AM PST by ChefKeith (Life is GREAT with CoCo..........NASCAR...everything else is just a game!(Except War & Love))
[ Post Reply | Private Reply | To 13 | View Replies]

To: ChefKeith

Download 1.5.0 here:

http://java.sun.com/j2se/1.5.0/download.jsp

Choose the JRE because you don't need the extra developer tools.

This has a huge number of bug fixes in it over the 1.4.2 series.


16 posted on 11/24/2004 12:40:10 AM PST by ScottM1968
[ Post Reply | Private Reply | To 15 | View Replies]

To: Eagle9

OK,,silly question for those of us who are technically impaired.

I am not a developer, just an internet computer user. I use FF 1.0. Do I need to worry about this and DL this new Java jive thing?


Thanks!


17 posted on 11/24/2004 12:41:19 AM PST by Khurkris (That sound you hear coming from over the horizon...thats me laughing.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ChefKeith

http://javashoplm.sun.com/ECom/docs/Welcome.jsp?StoreId=22&PartDetailId=jre-1.5.0-oth-JPR&SiteId=JSC&TransactionId=noreg


Probably


18 posted on 11/24/2004 12:41:54 AM PST by dennisw (G_D: Against Amelek for all generations)
[ Post Reply | Private Reply | To 15 | View Replies]

To: dennisw
Probably ?

How probably????? Heck is this something the average web surfer even needs?

19 posted on 11/24/2004 12:45:41 AM PST by ChefKeith (Life is GREAT with CoCo..........NASCAR...everything else is just a game!(Except War & Love))
[ Post Reply | Private Reply | To 18 | View Replies]

To: ScottM1968

see 18 & 19 please


20 posted on 11/24/2004 12:46:45 AM PST by ChefKeith (Life is GREAT with CoCo..........NASCAR...everything else is just a game!(Except War & Love))
[ Post Reply | Private Reply | To 16 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-52 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson