Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Sun/Netscape Java Virtual Machine Bytecode Verifier Vulnerability

A vulnerability in the Sun and Netscape Java Virtual Machine has been reported. The vulnerability is related to the bytecode verifier, a component of the Java compiler that ensures legal structure of Java instructions. According to the report, it is possible to construct bytecode that will cause objects to be instantiated without proper initialization. One known method of exploiting this vulnerability can allow for read/write access to system files despite the security constraints of the Applet sandbox.







 

Privacy Statement
Copyright 2009, SecurityFocus