26 Replies - 5681 Views - Last Post: 10 March 2013 - 09:52 PM
#16
Re: Java Zero Day
Posted 11 January 2013 - 10:30 PM
http://appleinsider....ava-7-from-os-x
#17
Re: Java Zero Day
Posted 12 January 2013 - 06:58 AM
jon.kiparsky, on 12 January 2013 - 02:29 AM, said:
As far as I can tell, the exploit targets the browser plug-in. The java developer who doesn't run random applets faces no added security risk for having java on their machine.
It's a new exploit found after the patching of two previous ones, which makes statements similar to: "I'm starting to think that Java doesn't care about security" or "Java is unablle to keep anything secure." completely idiotic.
#18
Re: Java Zero Day
Posted 12 January 2013 - 08:37 AM
What's a reasonable turnaround time for this kind of thing, in your opinion? Six months? A year?
#19
Re: Java Zero Day
Posted 12 January 2013 - 09:27 AM
farrell2k, on 12 January 2013 - 08:58 AM, said:
jon.kiparsky, on 12 January 2013 - 02:29 AM, said:
As far as I can tell, the exploit targets the browser plug-in. The java developer who doesn't run random applets faces no added security risk for having java on their machine.
It's a new exploit found after the patching of two previous ones, which makes statements similar to: "I'm starting to think that Java doesn't care about security" or "Java is unablle to keep anything secure." completely idiotic.
http://developers.sl...-hole-in-august
I think that 4-5 months is a little bit "Oracle isn't doing enough about security."
http://www.forbes.co...itical-bug-fix/
Quote
This post has been edited by xclite: 12 January 2013 - 09:30 AM
#20
Re: Java Zero Day
Posted 12 January 2013 - 09:35 AM
#21
Re: Java Zero Day
Posted 12 January 2013 - 05:44 PM
jon.kiparsky, on 12 January 2013 - 03:37 PM, said:
What's a reasonable turnaround time for this kind of thing, in your opinion? Six months? A year?
I only posted that because you wanted some technical info about the bugs.
Turn around time for a fix? The sooner the better, I suppose.
Dogstopper, on 12 January 2013 - 04:35 PM, said:
Good question. Regarding the last bug:
"Code execution was confirmed with the latest Oracle and IBM Java 7 web browser plugin. IcedTea-Web using OpenJDK7 blocks this exploit by not allowing applet to change the SecurityManager (which is allowed in Oracle and IBM Java plugin)."
I'd assume it is vulnerable as well.
This post has been edited by farrell2k: 12 January 2013 - 05:49 PM
#22
Re: Java Zero Day
Posted 13 January 2013 - 08:18 PM
Quote
The exploit conditions for these vulnerabilities are the same. To be successfully exploited, an attacker needs to trick an unsuspecting user into browsing a malicious website. The execution of the malicious applet within the browser of the unsuspecting users then allows the attacker to execute arbitrary code in the vulnerable system. These vulnerabilities are applicable only to Java in web browsers because they are exploitable through malicious browser applets.
With this Security Alert, and in addition to the fixes for CVE-2013-0422 and CVE-2012-3174, Oracle is switching Java security settings to “high” by default. The high security setting requires users to expressly authorize the execution of applets which are either unsigned or are self-signed. As a result, unsuspecting users visiting malicious web sites will be notified before an applet is run and will gain the ability to deny the execution of the potentially malicious applet. Note also that Java SE 7 Update 10 introduced the ability for users to easily disable Java in their browsers through the Java Control Panel.
cite
#23
Re: Java Zero Day
Posted 13 January 2013 - 08:22 PM
Quote
"We don't dare to tell users that it's safe to enable Java again," said Gowdiak, a researcher with Poland's Security Explorations.
An Oracle spokeswoman declined to comment on Gowdiak's analysis.
http://news.yahoo.co...05--sector.html
#24
Re: Java Zero Day
Posted 13 January 2013 - 08:23 PM
If anyone's taken the time to look at the details, please fill us in - but based on the quoted post, it doesn't look like there's much there.
This post has been edited by jon.kiparsky: 13 January 2013 - 08:26 PM
#25
Re: Java Zero Day
Posted 15 January 2013 - 06:52 AM
#26
Re: Java Zero Day
Posted 17 January 2013 - 02:31 PM
Quote
http://www.javaworld...java-patch.html
#27
Re: Java Zero Day
Posted 10 March 2013 - 09:52 PM
http://www.javaworld...-bit9-hack.html
|
|

New Topic/Question
Reply






MultiQuote






|