Sun Squashes Critical Java Bugs

執筆者
Ryan Naraine
Ryan Naraine
Published: Jun 14, 2005
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Network computing giant Sun Microsystems has rolled out patches for a pair of “highly critical” flaws in the Sun JRE (Java Runtime Environment) sandbox and the Java Web Start technology.

The Santa Clara, Calif.-based company said the bugs can be exploited by a malicious hacker to execute arbitrary code on vulnerable systems.

The more serious of the two vulnerabilities, which affects the Java Runtime Environment, may allow an untrusted applet to elevate its privileges.

“For example, an applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet,” the company said in a published advisory.

Sun said the issue can occur in Java 2 Platform Standard Edition (J2SE) 5.0 and in 5.0 Update 1 for Windows, Solaris and Linux; as well as in J2SE 1.4.2_07 and earlier 1.4.2 releases for Windows, Solaris and Linux.

Suns J2SE 1.3.1_xx releases for Windows, Solaris and Linux are not affected.

Suns JRE provides the libraries, the Java Virtual Machine and other components to run applets and applications written in the Java programming language.

Download locations for patches have been included in the Sun security alert.

/zimages/6/28571.gifClick hereto read about network gear makers issuing security cautions.

In a separate advisory, Sun Microsystems Inc. confirmed a privilege escalation security hole in Java Web Start, the technology used to deploy stand-alone applications over a network.

Affected releases include Java Web Start in J2SE 5.0 and 5.0 Update 1 for Windows, Solaris and Linux.

Sun recommends that users disable Java Web Start applications from being launched from a Web browser. Instructions for the browser workaround and information on patching are available on Suns Web site.

/zimages/6/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。