Short Name |
HTTP:STC:JAVA:MAL-JNLP-FILE
|
Severity |
High
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
Malicious Java JNLP File
|
Release Date |
2005/05/16
|
Update Number |
1213
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+
|
HTTP: Malicious Java JNLP File
This signature detects attempts to exploit a known vulnerability in the Java JRE implementation. Attackers can create a malicious JNLP file that, when loaded by a user, can compromise the user's computer.
Extended Description
A remote unauthorized-access vulnerability affects Java Web Start because the application fails to properly validate user-supplied input before considering it trusted.
An attacker may leverage this issue to gain unauthorized read/write access to affected computers. Other attacks may also be possible. Note that unauthorized access granted in this way will be with the privileges of the unsuspecting user that visits a malicious website.
Reports from Harry Johnston indicate the OraClient 10g component of Oracle Database Server 10g incorporates a vulnerable version of the Java Runtime Environment and is therefore vulnerable to this issue.
Affected Products
- Apple Mac OS X 10.0.0
- Apple Mac OS X 10.0.0 3
- Apple Mac OS X 10.0.1
- Apple Mac OS X 10.0.2
- Apple Mac OS X 10.0.3
- Apple Mac OS X 10.0.4
- Apple Mac OS X 10.1.0
- Apple Mac OS X 10.1.1
- Apple Mac OS X 10.1.2
- Apple Mac OS X 10.1.3
- Apple Mac OS X 10.1.4
- Apple Mac OS X 10.1.5
- Apple Mac OS X 10.2.0
- Apple Mac OS X 10.2.1
- Apple Mac OS X 10.2.2
- Apple Mac OS X 10.2.3
- Apple Mac OS X 10.2.4
- Apple Mac OS X 10.2.5
- Apple Mac OS X 10.2.6
- Apple Mac OS X 10.2.7
- Apple Mac OS X 10.2.8
- Apple Mac OS X 10.3.0
- Apple Mac OS X 10.3.1
- Apple Mac OS X 10.3.2
- Apple Mac OS X 10.3.3
- Apple Mac OS X 10.3.4
- Apple Mac OS X 10.3.5
- Apple Mac OS X 10.3.6
- Apple Mac OS X 10.3.7
- Apple Mac OS X 10.3.8
- Apple Mac OS X Server 10.0.0
- Apple Mac OS X Server 10.1.0
- Apple Mac OS X Server 10.1.1
- Apple Mac OS X Server 10.1.2
- Apple Mac OS X Server 10.1.3
- Apple Mac OS X Server 10.1.4
- Apple Mac OS X Server 10.1.5
- Apple Mac OS X Server 10.2.0
- Apple Mac OS X Server 10.2.1
- Apple Mac OS X Server 10.2.2
- Apple Mac OS X Server 10.2.3
- Apple Mac OS X Server 10.2.4
- Apple Mac OS X Server 10.2.5
- Apple Mac OS X Server 10.2.6
- Apple Mac OS X Server 10.2.7
- Apple Mac OS X Server 10.2.8
- Apple Mac OS X Server 10.3.0
- Apple Mac OS X Server 10.3.1
- Apple Mac OS X Server 10.3.2
- Apple Mac OS X Server 10.3.3
- Apple Mac OS X Server 10.3.4
- Apple Mac OS X Server 10.3.5
- Apple Mac OS X Server 10.3.6
- Apple Mac OS X Server 10.3.7
- Apple Mac OS X Server 10.3.8
- Conectiva Linux 10.0.0
- Gentoo Linux
- Novell Linux Desktop 9
- Sun Java Web Start 1.2.0
- Sun JRE (Linux Production Release) 1.3.0 .0
- Sun JRE (Linux Production Release) 1.3.0 .0 02
- Sun JRE (Linux Production Release) 1.3.0 .0 05
- Sun JRE (Linux Production Release) 1.3.1 01
- Sun JRE (Linux Production Release) 1.3.1 01A
- Sun JRE (Linux Production Release) 1.3.1 04
- Sun JRE (Linux Production Release) 1.3.1 08
- Sun JRE (Linux Production Release) 1.4.1
- Sun JRE (Linux Production Release) 1.4.2
- Sun JRE (Linux Production Release) 1.4.2 01
- Sun JRE (Linux Production Release) 1.4.2 02
- Sun JRE (Linux Production Release) 1.4.2 03
- Sun JRE (Linux Production Release) 1.4.2 04
- Sun JRE (Linux Production Release) 1.4.2 05
- Sun JRE (Linux Production Release) 1.4.2 06
- Sun JRE (Solaris Production Release) 1.3.0 01
- Sun JRE (Solaris Production Release) 1.3.0 03
- Sun JRE (Solaris Production Release) 1.3.0 04
- Sun JRE (Solaris Production Release) 1.3.1
- SuSE Linux Desktop 1.0.0
- SuSE Linux Enterprise Server for S/390 9.0.0
- SuSE Linux Personal 8.2.0
- SuSE Linux Personal 9.0.0
- SuSE Linux Personal 9.0.0 X86 64
- SuSE Linux Personal 9.1.0
- SuSE Linux Personal 9.1.0 X86 64
- SuSE Linux Personal 9.2.0
- SuSE Linux Personal 9.2.0 X86 64
- SuSE Linux Personal 9.3.0
- SuSE Linux Personal 9.3.0 X86 64
- SuSE Linux Professional 8.2.0
- SuSE Linux Professional 9.0.0
- SuSE Linux Professional 9.0.0 X86 64
- SuSE Linux Professional 9.1.0
- SuSE Linux Professional 9.1.0 X86 64
- SuSE Linux Professional 9.2.0
- SuSE Linux Professional 9.2.0 X86 64
- SuSE Linux Professional 9.3.0
- SuSE Linux Professional 9.3.0 X86 64
- SuSE Novell Linux Desktop 1.0.0
- SuSE Novell Linux Desktop 9.0.0
- SuSE Open-Enterprise-Server 9.0.0
- SuSE SUSE Linux Enterprise Server 9
References