PT-2003-2466 · Sun+1 · Sun Java Plug-In+1

Published

2003-12-31

·

Updated

2008-09-05

·

CVE-2003-1521

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Sun Java Plug-In versions 1.4 through 1.4.2 02
Description The issue allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, violating the Java security model.
Recommendations For Sun Java Plug-In versions 1.4 through 1.4.2 02, consider disabling the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class as a temporary workaround until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-1521

Affected Products

Apache Crimson
Sun Java Plug-In