|
|
| |
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2004-1029
The original article can be found at: http://www.securityfocus.com/bid/11726
|
| |
Vulnerable Systems:
* Symantec Gateway Security 5400 2.0.1
* Symantec Gateway Security 5400 2.0
* Symantec Enterprise Firewall 8.0 Solaris
* Symantec Enterprise Firewall 8.0 NT/2000
* Symantec Enterprise Firewall 8.0
A vulnerability is reported to exist in the access controls of the Java to JavaScript data exchange within web browsers that employ the Sun Java Plug-in. Reports indicate that it is possible for a malicious website that contains JavaScript code to exploit this vulnerability to load a dangerous Java class and to pass this class to an invoked applet.
Vendor Status:
Symantec as issued an update for this vulnerablity
Patch Availability:
http://securityresponse.symantec.com/avcenter/security/Content/2005.01.04.html
CVE Information:
CVE-2004-1029
|
|
|