On March 4, 2002, Microsoft released the first version of this bulletin. On March 18, 2002, Microsoft re-released this bulletin to make customers aware of an additional vulnerability that is eliminated by the updated VM (Microsoft VM build 3805). Customers who have previously installed the new build do not need to take any additional action.
new build of the VM (build 3805) is available, which eliminates two security vulnerabilities. The first vulnerability is the result of a flaw affecting how Java requests for proxy resources are handled. A malicious Java applet could exploit this flaw to re-direct web traffic once it has left the proxy server to a destination of the attacker’s choice
|