Java Entrepreneur

Java Application Development & Entrepreneurship

Vulnerability reported in Sun Java System Web Proxy

Sun Java System Web Proxy vulnerability.jpg

Vulnerability has been reported in Java System Web Proxy. Remote exploitation of multiple stack based buffer overflows allows unauthenticated attackers to execute arbitrary code with super user privileges. The problem has been reported within sockd daemon and it can lead to buffer overflow by manipulation of bytes during protocol negotiation.

Arbitary code can be executed with the privileges of user running sockd. No kind of authentication is required and the attacker just needs to open a session with the SOCKS server. In order to counter this threat SOCKS proxy server should be disabled and firewalls should also be deployed.

Info & Utils

Published in Monday, May 28th, 2007, at 11:53 am, and filed under Security.

Do it youself: Digg it!Save on del.icio.usMake a trackback.

Previous text: .

Next text: .

Leave a Reply

Java Entrepreneur © 2007. Theme Squared created by Rodrigo Ghedin.