Sun Java Web Start Security VulnerabilityPublished--Fixed in Security Update 2005-02

Sun just published "Security Vulnerability With Java Web Start" which, according to Apple, has already been fixed for Mac OS X in Security Update 2005-002. Macs that have already installed Security Update 2005-002 do not need to re-install it. Here are the details:

Available for: Java 1.4.2
CVE-ID: CAN-2005-0418
Impact: Updates Java to address an issue in Java Web Start that allows an untrusted application to elevate its privileges Description: A vulnerability in Java Web Start allows an untrusted application to elevate its privileges. For example an application may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the Java Web Start application. Releases prior to Java 1.4.2 are not affected by this vulnerability. Further information is available in Document ID 57740 from Sun's security Web site.

Security Update 2005-002 may be obtained from the Software Update pane in System Preferences, or as a standalone updater at Apple's Software Downloads Web site. [Bill Fox]



Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Security · This month in the archive