4 ms·
But the point still stands that this specific exploit is NOT a JVM exploit? Is it an actual exploit of the JVM implementation, or just the libraries? The probl
by pslam 14y ago
But the point still stands that this specific exploit is NOT a JVM exploit? Is it an actual exploit of the JVM implementation, or just the libraries?
The problem has always been that Sun shipped way too big a runtime for Java applets - the entire Java SE - when they should have made a third class ("edition") for browsers. That's a huge attack surface, and that's were most of the exploits have been, including this one, unless someone knows otherwise.
- pjmlp 14y agoRegardless of what is being exploited it is only effective in Oracle's implementation. Every JVM vendor has their own implementation, both runtime and libraries.