Welcome Guest ( Log In | Register )

  Recent Software News
123 Flash Chat - Pocket PC Chat Mod...
Google Plugs Cookie-Theft Data Leak
Phel Trojan targets Windows flaw
Cabir cell phone threat worsens
19 LingvoSoft dictionaries for Wind...
  Recent Gaming News
Electronic Arts to buy into Ubi Sof...
Halo 2, San Andreas key drivers of ...
Sony Says All Systems Go for PSP La...
Nvidia to work on PlayStation 3 chi...
New Command & Conquer Game Unveiled
  Recent Reviews
 · CoolerMaster Aerogate 3 A...
 · CoolerMaster AquaGate Wat...
 · OCZ Copper BGA Ramsinks
 · Mapower Warps Portable 3....
 · Vantec - PCI & RAM Slot P...
  Recent Forum Posts
Robosapien
Microsoft Anti-Spyware
Windows XP Sp2 Problems
How to enable use of nvidia dr...
Leadtek A350XT TDH and overclo...
  Announcement

Welcome to AusPCWorld - Australia's Leading PC Technology News & Reviews site.



> AusPCWorld > Tech News > Vulnerability hits Java for cell phones






   
Vulnerability hits Java for cell phones
Posted by admin on 24 Oct 2004 - 07:13 0 comments
Previous Post | Tech News | Next Post
 
A Polish researcher has found two vulnerabilities in the cell phone version of Sun Microsystems' Java software that under unusual circumstances could let a malicious program read private information or render a phone unusable.

The flaws are difficult to exploit because malicious programs must be tailored to a specific model of cell phone, said Adam Gowdiak, a 29-year-old security researcher with the Poznan Supercomputing and Networking Center who discovered the vulnerabilities. He figured out how to attack a Nokia 6310i mobile phone, but the effort took four months, he said in a Friday posting to the BugTraq vulnerability mailing list.

Before the vulnerabilities could be exploited, a phone user would have to download and run a malicious Java program, called a midlet, Gowdiak said in an e-mail interview. He's not aware of a way to automate an attack. He notified Sun of the vulnerabilities in August, and the company said it sent Java licensees a patched version of the vulnerable component, called the Java bytecode verifier, within two weeks. "We have not seen any attempts to exploit this vulnerability, but if there is one, the user can simply delete...the applications they downloaded from an untrusted source," said Eric Chu, Sun's director of marketing for the Java 2 Micro Edition, or J2ME, software.

News source: ZDNet



There are 0 additional comments, Post a comment | View printable post | Open/Close All Comments


Add A new comment
Name: (Register)
Email: (optional)
Quick HTML: (help)
  Close current tag   Standard Mode
  Close all tags   Enhanced Mode
Comment:


Smilies
(help)
Parse URL's: (will automatically add [url] [/url] round the web addresses in your comment)