Filed in archive
Security
by gautam on July 10, 2007

Marc Maiffret, Chief hacking officer, eEye Digital Security stated in an advisory warning:
Sun is one of the few companies that is still unable to coordinate the simultaneous release of security patches. This organizational failure puts customers at undue risk. Hopefully in the future Sun will be able to bring their security and development process out of the dark ages. The flaw, which affects Windows-based machines, is a stack buffer overflow in WebStart, a utility that manages downloaded Java applications. The vulnerability can be exploited simply by luring a victim to a booby-trapped web site, allowing an attacker to silently execute code that will hijack the machine.
It is the gap of eleven days which has brought Sun's security team under the scanner and its all due to the fact that hackers are adept at reverse engineering the patch for getting a clue as to how the vulnerability being fixed behaved and using that same knowledge they are able to design the exploits. The vulnerability should have been fixed on all platforms at the same time and this mistake might give a chance to hackers to again bring their heads up and cause trouble.
Trackback: http://publish.creative-weblogging.com/publish/mt-tb.pl/80224
Mr Wong
Vote for Sun security team receives criticism for poor handling of Java security update:
|
Rating: 10.00 out of 1 vote(s) cast.
|
Subscribe
Use the search to look for other interesting posts
| RSS | See all blog subscribe options |
|
What is RSS? | |
| Yahoo! |
|
| Addthis |
|
| Bloglines |
|
| Newsletter | |
| Follow us on Twitter! |










