Full Disclosure mailing list archives

Re: info on JRE < 1.4.2_04 vulnerability


From: Valdis.Kletnieks () vt edu
Date: Tue, 11 May 2004 14:14:44 -0400

On Tue, 11 May 2004 11:19:38 EDT, "Mark W. Webb" <mark () dolphtech com>  said:

I am confused, being a semi-newbie, how this can be a vulnerability 
without an exploit.  Is it just that Sun does not want to admit that 
there is an exploit?  Does anyone have any more information on this that 
they can provide?

The fact that nobody has produced a public piece of code that actually
demonstrates the exploit doesn't mean that there isn't a bug.

As an analogy - imagine if a car manufacturer issued a recall, saying "under
certain timing conditions of multiple doors closing at almost the same time,
the power locks may fail to actually lock all the doors".  That doesn't tell
you anything about whether any cars have actually been stolen because a door
didn't get locked when it should have....

Attachment: _bin
Description:


Current thread: