First published: Thu Mar 24 2005(Updated: )
Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06, on Mac OS X, allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file. NOTE: it is highly likely that this item will be MERGED with CVE-2005-0836.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun J2se | =1.4.2_02 | |
Sun J2se | =1.4.2_05 | |
Sun J2se | =1.4.2_03 | |
Sun J2se | =1.4.2_04 | |
Sun J2se | =1.4.2_06 | |
Sun J2se | =1.4.2_01 | |
Sun J2se | =1.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0418 is considered to have a moderate severity level due to the potential for untrusted applications to gain elevated privileges.
To fix CVE-2005-0418, it is recommended to upgrade to a later version of J2SE that addresses this vulnerability.
CVE-2005-0418 affects Sun J2SE versions 1.4.2 up to and including 1.4.2_06 on Mac OS X.
CVE-2005-0418 is classified as an argument injection vulnerability allowing untrusted applications to manipulate system properties.
Yes, CVE-2005-0418 can be exploited remotely through malicious JNLP files delivered via network or web services.