Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > News > Tech News > Oracle issues emergency Java patch, but holes persist

Oracle issues emergency Java patch, but holes persist
Thread Tools
MacNN Staff
Join Date: Jul 2012
Status: Offline
Reply With Quote
Jan 14, 2013, 05:52 AM
 
Oracle has issued an emergency patch for Java, its popular web technology. Security researchers last week uncovered a zero-day exploit that is being exploited by hackers in two malware tookits prompting the US government to issue a warning to PC owners. Although the patch addresses certain holes, Reuters reports that a security analyst still believes that the platform remains vulnerable.

According to Oracle, the patch addresses remotely exploitable vulnerabilites that only affect Oracle Java 7 versions. The company, of course, recommends that users apply the patch as soon as possible. The patch closes a vulnerability that allowed an attacker to trick an unsuspecting user into visiting a maliciously constructed website. The threat only affects Java in web browsers and not other forms of Java and is executed through malicious browser applets. To further help Java from being more susceptible to attacks in future, Oracle has adjusted default security settings in Java to 'High.' By taking this step, users who are unknowingly redirected to a malicious website will be notified before an applet is run, giving users the option to deny the applet permission to run. Oracle also says that the Java SE 7 Update 11 also makes it easier for users to disable Java in their browsers through a Java Control Panel.
(Last edited by NewsPoster; Jan 14, 2013 at 04:02 PM. )
     
Junior Member
Join Date: Jan 2007
Location: SF
Status: Offline
Reply With Quote
Jan 14, 2013, 01:05 PM
 
"Oracle also says that the Java SE 7 Update 10"
Wait. Did Oracle make that specific reference to the previous version of Java, or was that supposed to reference the current version, Java SE 7 Update 11?

It's no less true, but certainly more confusing. The line before it could use a spell check and some punctuation as well.
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 03:51 AM.
All contents of these forums © 1995-2013 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2013, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2