Full Disclosure mailing list archives
Re: info on JRE < 1.4.2_04 vulnerability
From: Valdis.Kletnieks () vt edu
Date: Tue, 11 May 2004 14:14:44 -0400
On Tue, 11 May 2004 11:19:38 EDT, "Mark W. Webb" <mark () dolphtech com> said:
I am confused, being a semi-newbie, how this can be a vulnerability without an exploit. Is it just that Sun does not want to admit that there is an exploit? Does anyone have any more information on this that they can provide?
The fact that nobody has produced a public piece of code that actually demonstrates the exploit doesn't mean that there isn't a bug. As an analogy - imagine if a car manufacturer issued a recall, saying "under certain timing conditions of multiple doors closing at almost the same time, the power locks may fail to actually lock all the doors". That doesn't tell you anything about whether any cars have actually been stolen because a door didn't get locked when it should have....
Attachment:
_bin
Description:
Current thread:
- info on JRE < 1.4.2_04 vulnerability Mark W. Webb (May 11)
- Re: info on JRE < 1.4.2_04 vulnerability Valdis . Kletnieks (May 11)