OSVDB ID: 50500

Title: Sun Java JDK / JRE Deserializing Calendar Object Privilege Escalation

Info

Disclosure

Dec 03, 2008

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

A security vulnerability in the Java Runtime Environment (JRE) related to deserializing calendar objects may allow an untrusted applet or application to escalate privileges. For example, an untrusted applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet.

Classification

Location: Local / Remote
Impact: Loss of Confidentiality, Loss of Integrity
Solution: Upgrade
Exploit: Exploit Public, Exploit Commercial
Disclosure: Vendor Verified

Solution

Upgrade to version JDK/JRE 5.0 Update 17, JDK/JRE 6 Update 11, SDK/JRE 1.4.2_19, SDK/JRE 1.3.1_24 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Unknown or Incomplete

References

Credit

  • Sami Koivu -


Direct URL: http://osvdb.org/50500