Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Re: Re: Sun Java Plugin arbitrary package access vulnerability
From: "Exchange" <pauls () utdallas edu>
Date: Thu, 25 Nov 2004 12:23:20 -0600

----- Original Message ----- 
From: "Alla Bezroutchko" <alla () scanit be>
To: <bugtraq () securityfocus com>; <full-disclosure () lists netsys com>
Sent: Thursday, November 25, 2004 4:33 AM
Subject: [Full-disclosure] Re: Sun Java Plugin arbitrary package access

As noted by rodmoses(at)yahoo(dot)com Opera remains vulnerable even
after the upgrade of JVM to version 1.4.2_06. (tested on Windows XP SP2,
Opera 7.54, J2SE 1.4.2_06).

This wasn't mentioned in the original disclosure announcement, but is it
safe to assume that jre-1.5.0 would *not* be vulnerable?  Or has it not been

Paul Schmehl (pauls () utdallas edu)
Adjunct Information Security Officer
University of Texas at Dallas
AVIEN Founding Member

Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]