Re: CVE-2009-2475

David-Sarah Hopwood <[email protected]>
Newsgroups gmane.comp.lang.e.general
Message-ID <[email protected]>
David Wagner wrote:
> Does anyone know anything more about the Java vulnerability
> CVE-2009-2475?  The only information I could find (see below)
> refers to problems with mutable static variables.
> 
> Would Joe-E have prevented these flaws?  (Joe-E bans mutable
> static variables.)

Yes, it would (if the code in question were either Joe-E, or not exposed
by taming decisions).

> Several, potential information leaks were found in various mutable static
> variables. These could be exploited in application scenarios that execute
> untrusted scripting code.

I'm not sure why this is referred to only as an information leak; it's
both an information leak and an integrity issue (since obviously, code
using these variables cannot be defensively consistent if they are
globally mutable).

Any public static non-final variable in a Java API is necessarily a bug.
So are static variables that are final but reference mutable objects,
when access to those objects is not controlled by some security check.

-- 
David-Sarah Hopwood  ⚥  http://davidsarah.livejournal.com

_______________________________________________
e-lang mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/e-lang
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.