Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://sunsolve.sun.com/search/document.do?assetkey=1-26-57591-1&searchclause=%22category:security%22%20%22availability,%20security%22
http://www.securityfocus.com/archive/1/382072
http://marc.theaimsgroup.com/?l=bugtraq&m=110125046627909 http://www.vuxml.org/freebsd/ac619d06-3ef8-11d9-8741-c942c075aa41.html
Insight
The following packages are affected:
jdk
linux-jdk
linux-sun-jdk
linux-blackdown-jdk
linux-ibm-jdk
diablo-jdk
diablo-jre
CVE-2004-1029
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code.
Severity
Classification
-
CVE CVE-2004-1029 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities