webappsec October 2010 archive
Main Archive Page > Month Archives  > webappsec archives
webappsec: Java Multiple Issues

Java Multiple Issues

From: Early Warning <seclist_at_nospam>
Date: Thu Oct 21 2010 - 07:44:48 GMT
To: webappsec@securityfocus.com, full-disclosure@lists.grok.org.uk, bugtraq@securityfocus.com, vuln@secunia.com

Hi all and sorry for cross post,
after several months since I contacted Oracle informing them about ten
issues on Java applet security, they finally released an Java 6 update
22 which fixes several security issues

In particular the issues are the following, sorted by impact:

    * Information Disclosure:
          - 17364779 NETWORKINTERFACE HASHCODE PROBLEM
          - 17322679 JAVA APPLET DNS IP DISCLOSURE
    * User Assisted Arbitrary Execution:
          - 17322757 ZERO TERMINATOR ALLOWS JNLP SHORTCUTS
          - 17322755 NEW LINES IN JNLP TITLE ARE COPIED INTO LNK FILES
    * Network and WEB Attacks:
          - 17322683 HTTP REQUEST SPLITTING WITH JAVA ADDREQUESTPROPERTY
          - 17764405 DNS REBINDING ISSUE
          - 17322681 JAVA APPLET SAME IP HOST ACCESS

You can read all details here:
http://blog.mindedsecurity.com/2010/10/java-6u21-seven-issues-summary.html

Disclosure Timeline:
20th Apr - 6 May 2010: Advisories sent to Oracle
25th June 2010: Oracle Confirms all issues
12 Oct 2010: Java update 22 released which fixes 7 out of 10 issues.
11-20 Oct 2010: Minded Security Advisories pubicly disclosed.

Cheers,
Stefano Di Paola

-- Stefano Di Paola Chief Technology Officer, Lead Auditor ISO 27001 Minded Security - Application Security Consulting This list is sponsored by Cenzic -------------------------------------- Let Us Hack You. Before Hackers Do! It's Finally Here - The Cenzic Website HealthCheck. FREE. Request Yours Now! http://www.cenzic.com/2009HClaunch_Securityfocus --------------------------------------