First published: Wed Dec 31 2003(Updated: )
Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Java Embedding Plugin | =1.4 | |
Sun Java Embedding Plugin | =1.4.2 | |
Sun Java Embedding Plugin | =1.4.2_01 | |
Sun Java Embedding Plugin | =1.4.2_02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1521 has a moderate severity level due to its potential for remote attackers to exploit the vulnerability.
To fix CVE-2003-1521, update to a later version of the Sun Java Plug-In that addresses this vulnerability.
The affected versions for CVE-2003-1521 include Sun Java Plug-In 1.4, 1.4.1, and 1.4.2 up to 1.4.2_02.
Yes, CVE-2003-1521 can be exploited remotely through the createXmlDocument method.
The impact of CVE-2003-1521 allows attackers to repeatedly access the floppy drive, violating the Java security model.