Re: [Full-Disclosure] Re: Sun Java Plugin arbitrary package access vulnerability

From: Exchange (pauls_at_utdallas.edu)
Date: 11/25/04

  • Next message: Todd Towles: "RE: [Full-Disclosure] Fwd: Hi, It's Me !!!!!"
    To: "Alla Bezroutchko" <alla@scanit.be>, <bugtraq@securityfocus.com>, <full-disclosure@lists.netsys.com>
    Date: Thu, 25 Nov 2004 12:23:20 -0600
    
    

    ----- Original Message -----
    From: "Alla Bezroutchko" <alla@scanit.be>
    To: <bugtraq@securityfocus.com>; <full-disclosure@lists.netsys.com>
    Sent: Thursday, November 25, 2004 4:33 AM
    Subject: [Full-Disclosure] Re: Sun Java Plugin arbitrary package access
    vulnerability
    >
    > As noted by rodmoses(at)yahoo(dot)com Opera remains vulnerable even
    > after the upgrade of JVM to version 1.4.2_06. (tested on Windows XP SP2,
    > Opera 7.54, J2SE 1.4.2_06).
    >
    This wasn't mentioned in the original disclosure announcement, but is it
    safe to assume that jre-1.5.0 would *not* be vulnerable? Or has it not been
    tested?

    Paul Schmehl (pauls@utdallas.edu)
    Adjunct Information Security Officer
    University of Texas at Dallas
    http://www.utdallas.edu/
    AVIEN Founding Member

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Todd Towles: "RE: [Full-Disclosure] Fwd: Hi, It's Me !!!!!"

    Relevant Pages