[37514] in bugtraq
Re: Sun Java Plugin arbitrary package access vulnerability
daemon@ATHENA.MIT.EDU (Ken S)
Thu Nov 25 15:31:54 2004
Message-ID: <93bd852904112421002571c6a8@mail.gmail.com>
Date: Wed, 24 Nov 2004 23:00:30 -0600
From: Ken S <ken.securitylist@gmail.com>
Reply-To: Ken S <ken.securitylist@gmail.com>
To: bugtraq@securityfocus.com
In-Reply-To: <200411241859.iAOIxvDP000794@dim.ucsd.edu>
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
After installing a new version of the JRE on two machines, IE and
Firefox both report the plug-in as 1.4.2_06. For browsing to unknown
sites, it would appear that there is no need to uninstall the older
versions, unless there is a way for the javascript code to call a
lower version of the JRE. Hopefully, that's not possible.