New Java security hole affects desktops and servers

Adam Gowdiak, who has made a name for himself by finding flaws in Java, has reported a new vulnerability. Security issue 61, according to Gowdiakā€™s tally, affects current versions of Java SEĀ 7, including the very latest release version 1.7.0_21-b11. The hole is once again present in the Reflection API and allows attackers to completely bypass the languageā€™s sandbox to access the underlying system. Gowdiak has not published any further details about the vulnerability in order to give Oracle time to patch the problem. This means that there are now three vulnerabilities discovered by Gowdiak that still require fixes: problems 54, 56 and 61 as numbered by him. ...

April 23, 2013 Ā· 1 min Ā· 195 words Ā· Omid Farhang

Java 8 release schedule delayed for renewed focus on security

ISC Handler Rob V pointed out a blog post from Oracleā€™sĀ Mark Reinhold stating thatĀ Oracle has ā€œmounted an intense effort to address those issues in a series of critical-patch update releasesā€ and that theyā€™ve also upgraded their ā€œdevelopment processes to increase the level of scrutiny applied to new code, so that new code doesnā€™t introduce new vulnerabilities.ā€ Framing statements state that Oracle: ...

April 20, 2013 Ā· 1 min Ā· 144 words Ā· Omid Farhang

Java zero day vulnerability actively used in targeted attacks

ZDNet: Security researchers from FireEye, AlienVault, and DeependResearch have intercepted targeted malware attacks utilizing the latest Java zero day exploit. The vulnerability affects Java 7 (1.7) Update 0 to 6. It does not affect Java 6 and below. Based on related reports, researchers were able to reproduce the exploit on Windows 7 SP1 with Java 7 Update 6. Thereā€™s also a Metasploit module available. ...

August 27, 2012 Ā· 1 min Ā· 189 words Ā· Omid Farhang

Java 6 Update 27 released

Javaā„¢ SE 6 Update 27 The full internal version number for this update release is 1.6.0_27-b07 (where ā€œbā€ means ā€œbuildā€). The external version number is 6u27. Highlights This update release contains important enhancements for Java applications: Improved performance and stability Certification for Firefox 5 Update release notes: http://www.oracle.com/technetwork/java/javase/6u27-relnotes-444147.html Complete bug fix list: http://www.oracle.com/technetwork/java/javase/2col/6u27bugfixes-444150.html

August 25, 2011 Ā· 1 min Ā· 53 words Ā· Omid Farhang

Java surpasses Adobe kit as most attacked software

Researcher sees ā€˜unprecedented wave of Java exploitationā€™ Oracleā€™s Java framework has surpassed Adobe applications as the most attacked software package, according to a Microsoft researcher who warned she was seeing ā€œan unprecedented wave of Java exploitation.ā€ The spike began in the third-quarter of last year and has climbed steadily since, according to data reported on Monday by Holly Stewart, a member of the Microsoft Malware Protection Center. By the beginning of this year, the number of Java exploits ā€œhad well surpassed the total number of Adobe-related exploits we monitored,ā€ she said. ...

October 20, 2010 Ā· 2 min Ā· 329 words Ā· Omid Farhang