[<prev] [next>] [day] [month] [year] [list]
Message-ID: <005c01c61afb$3588a960$6701a8c0@pauls1337laptop>
Date: Mon, 16 Jan 2006 19:16:05 -0500
From: "Paul" <pvnick@...il.com>
To: <bugtraq@...urityfocus.com>,
<full-disclosure@...ts.grok.org.uk>
Subject: Sun Java Update Scheduler gets placed in
autostart without absolute path quotes
Name: SunJavaUpdateSched
Value: C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
…Meaning that Windows will attempt to execute C:\Program.exe first, and then
the rest of the path if that doesn’t exist.
Might be a bug in the old version – I haven’t updated yet. Not a very
critical bug, although the autostart is in HKLM, so users can install
malware on other users’ accounts.
Kind regards,
Paul Nickerson
Greyhats Security
--
No virus found in this outgoing message.
Checked by AVG Free Edition.
Version: 7.1.375 / Virus Database: 267.14.19/231 - Release Date: 1/16/2006
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists