3 ms·
Is it actually a JVM exploit, though? From FireEye's blog it sounds more like a library exploit which allows unconstrained clearing of memory, which then leads
by pslam 14y ago
Is it actually a JVM exploit, though? From FireEye's blog it sounds more like a library exploit which allows unconstrained clearing of memory, which then leads to a JVM escape because it blows away the JVM state. I wouldn't class that as a JVM exploit.
- pjmlp 14y agoYes, however there are hundreds of JVMs available in the wild. Oracle's one is just the reference version.
- pslam 14y agoBut the point still stands that this specific exploit is NOT a JVM exploit? Is it an actual exploit of the JVM implementation, or just the libraries? The problem has always been that Sun shipped way too big a runtime for Java applets - the entire Java SE - when they should have made a third class ("edition") for browsers. That's a huge attack surface, and that's were most of the exploits have been, including this one, unless someone knows otherwise.
- pjmlp 14y agoRegardless of what is being exploited it is only effective in Oracle's implementation. Every JVM vendor has their own implementation, both runtime and libraries.