Sun Microsystems Inc is working to fix a security hole in its Java Virtual Machine, according to Dr Edward Felten, director of Princeton University’s Secure Internet Programming Laboratory. The problem, which involves the JVM’s code source verifier, was reported a few weeks ago to Sun and Netscape Communications Corp by a graduate student in Germany. Microsoft Corp Internet Explorer browser users aren’t affected.

Sun is already sending out a patch for the Java Development Kit 1.1, and is in the final stages of releasing a version for JDK 1.2, which began shipping at the end of last year. The company said there was no evidence that anyone had used the flaw to gain access to a computer via web pages.