Re: [Full-disclosure] SEC-CONSULT SA-20050629-0

From: Moritz Naumann (info_at_moritz-naumann.com)
Date: 06/30/05

  • Next message: gerald: "Anyone else having serious repercussions from applying W2k sp4 se curity rollup patch?"
    Date: Thu, 30 Jun 2005 19:16:44 +0200
    To: Bernhard Mueller <research@sec-consult.com>
    
    

    > vulnerable versions:
    > ---------------
    >
    > javaprxy.dll 5.00.3810
    > internet explorer 6.0.2900.2180.xpsp_sp2_gdr.050301-1519
    >
    > these are the versions tested, other versions may of course be vulnerable.

    This is quite interesting.

    javaprxy.dll, aka 'Interface Proxy for Java' is/was part of the Virtual
    Machine for Java which M$ may no longer distribute. Its version number
    indicates that it was initially made for IE 5.x.

    You can download an archived distribution of the Virtual Machine for
    Internet Explorer at
    http://web.archive.org/web/20020201205255/http://www.microsoft.com/java/vm/dl_vm40.htm

    The file itself is here:
    http://web.archive.org/web/20020201205255/http://download.microsoft.com/download/vm/Install/3802/W9X2KMe/EN-US/msjavx86.exe

    This package, entitled "Microsoft VM build 3802 for Windows 95/98,
    Windows Me, Windows NT 4.0 and Windows XP", will, once extracted to the
    TEMP folder, reveal the "javaprxy.dll" file, version 5.00.3802.

    I don't know much about the contract M$ and Sun have, but it seems to me
    like M$ forgot to remove this file off the hard disks of people who have
    upgraded their I8N'd versions of Internet Explorer from v5.x to 6.x (or
    just v6 SP 0/1 to v6 SP 1/2).

    Just my five cents,
    Moritz


  • Next message: gerald: "Anyone else having serious repercussions from applying W2k sp4 se curity rollup patch?"

    Relevant Pages

    • Re: Waking up sleeping Java applications
      ... Not only that, the virtual machine ... With java you are running a program that is itself running a program. ... part of the Microsoft Windows environment. ... where Java dll's are held in memory to enable faster app startup. ...
      (comp.lang.java.programmer)
    • Re: windows virtual machine
      ... Microsoft is no longer allowed to provide its own Java ... Virtual Machine to Windows users. ... Microsoft Security Bulletin MS03-011 ...
      (microsoft.public.windowsxp.general)
    • Java Virtual Machine Launcher error
      ... I've had my Dell Inspiron 8600 with Windows XP Home since the middle of ... Approximately 2-3 weeks ago I started getting the following Java ... Virtual Machine Launcher error: ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: Sites that require Internet Explorer
      ... Not correct - we use webex on mac and/or Linux boxes (java) ... found is to run a virtual machine with Windows and IE... ...
      (Ubuntu)
    • Re: [Full-disclosure] SEC-CONSULT SA-20050629-0
      ... aka 'Interface Proxy for Java' is/was part of the Virtual ... Machine for Java which M$ may no longer distribute. ... You can download an archived distribution of the Virtual Machine for ... Windows Me, Windows NT 4.0 and Windows XP", will, once extracted to the ...
      (Full-Disclosure)