1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Java Web Start JNLP File Command Line Argument Injection Vulnerability

Discussion in 'Firefox, Thunderbird & SeaMonkey' started by Ramona, 2005/03/21.

Thread Status:
Not open for further replies.
  1. 2005/03/21
    Ramona

    Ramona Geek Member Alumni Thread Starter

    Joined:
    2001/12/31
    Messages:
    7,481
    Likes Received:
    2
    Java Web Start JNLP File Command Line Argument Injection Vulnerability
    NOTE:

    If you intend to install either Version 1.4.2_07, or Version 5.0/1.5.0, then first:

    Uninstall the existing Version of Sun Java, using the Add/Remove programs applet.
    If there is more than one version in existence, then uninstall ALL versions of Java.

    Reboot the PC

    Install 1.4.2_07, or 5.0/1.5.0
    (I personally recommend 5.0, also called 1.5.0)

    Ramona
     
  2. 2005/03/21
    James

    James Inactive

    Joined:
    2004/07/14
    Messages:
    1,004
    Likes Received:
    0
    Hi Ramona

    I did as you told me and uninstalled both versions and then re-installed version 5. I'm wondering about my wife's computer. She has version 1.4.06 and she just received a message that her "updates" are ready to be downloaded and installed... that is the new version 5. Can she go ahead and simply download this since it appears to be an automatic update from Java OR should she uninstall her older version and then go to Sun and download the newer version? And if this is the case, why does Sun give automatic upgrades like this? I just don't get it. Thanks.
     

  3. to hide this advert.

  4. 2005/03/21
    Ramona

    Ramona Geek Member Alumni Thread Starter

    Joined:
    2001/12/31
    Messages:
    7,481
    Likes Received:
    2
    James,

    Sure, your wife can go ahead and let the autoupdate install 5.0, but... and it's a big exception, I would go with a clean uninstall/install. Then there are no concerns about future problems...

    Ramona
     
  5. 2005/03/21
    Bmoore1129

    Bmoore1129 Geek Member

    Joined:
    2002/06/11
    Messages:
    1,675
    Likes Received:
    3
    James

    I did the auto update thing and ended up with both 1.4.2_07 and 1.5.0_02 on the computer. I then uninstalled both and installed the latest 1.5.0_02. The update function is really flakey and I won't use it again.
     
  6. 2005/03/21
    Ramona

    Ramona Geek Member Alumni Thread Starter

    Joined:
    2001/12/31
    Messages:
    7,481
    Likes Received:
    2
    Bill,

    Thanks for the confirmation on the auto update thingy. Back in the Communicator days, the Smart Update function was flaky too, and I think any user is better off with a nice clean unstall/install with a reboot in between.

    Ramona
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.