Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Determining Sun Java Vulnerability SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Determining Sun Java Vulnerability
A number of folks in the community have written in describing their experiences determining if they are vulnerable to the Java issue mentioned previously.
It appears that depending on your platform/configuration the sunjavaupdate scheduler may not apply the updates or notify the end-user in a timely manner. It appears to check for updates on the one month anniversary of the original install. So it may not check again for quite some time.
The Sun Java download site will determine if an update is needed if you're using IE and ActiveX:

Also the JavaTester site details all the different methods for determining what if any JDK/JRE is installed:

Also be aware many systems accumulate Java versions over time so you may have more than one installed.


49 Posts
Dec 1st 2005

Sign Up for Free or Log In to start participating in the conversation!