<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Oracle on Omid Farhang</title><link>https://omid.dev/tags/oracle/</link><description>Recent content in Oracle on Omid Farhang</description><image><title>Omid Farhang</title><url>https://omid.dev/images/bio-photo-150x150.jpg</url><link>https://omid.dev/images/bio-photo-150x150.jpg</link></image><generator>Hugo -- 0.163.3</generator><language>en-US</language><copyright>2026 Omid Farhang | All rights reserved.</copyright><lastBuildDate>Tue, 23 Apr 2013 20:23:35 +0000</lastBuildDate><atom:link href="https://omid.dev/tags/oracle/index.xml" rel="self" type="application/rss+xml"/><atom:link href="https://pubsubhubbub.appspot.com/" rel="hub"/><item><title>New Java security hole affects desktops and servers</title><link>https://omid.dev/2013/04/23/new-java-security-hole-affects-desktops-and-servers/</link><pubDate>Tue, 23 Apr 2013 20:23:35 +0000</pubDate><guid>https://omid.dev/2013/04/23/new-java-security-hole-affects-desktops-and-servers/</guid><description>&lt;p&gt;&lt;a href="https://omid.dev/images/2013/04/Java.jpg"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2013/04/Java-300x300.jpg" alt="Java" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Adam Gowdiak, who has made a name for himself by finding flaws in Java, has &lt;a href="http://seclists.org/fulldisclosure/2013/Apr/194"&gt;reported&lt;/a&gt; a new vulnerability. Security issue 61, according to Gowdiak&amp;rsquo;s tally, affects current versions of Java SE 7, including the very latest release version 1.7.0_21-b11.&lt;/p&gt;
&lt;p&gt;The hole is once again present in the &lt;a href="http://docs.oracle.com/javase/tutorial/reflect/"&gt;Reflection API&lt;/a&gt; and allows attackers to completely bypass the language&amp;rsquo;s sandbox to access the underlying system. Gowdiak has not published any further details about the vulnerability in order to give Oracle time to patch the problem. This means that there are now three vulnerabilities discovered by Gowdiak that still require fixes: problems 54, 56 and 61 as numbered by him.&lt;/p&gt;</description></item><item><title>Java 8 release schedule delayed for renewed focus on security</title><link>https://omid.dev/2013/04/20/java-8-release-schedule-delayed-for-renewed-focus-on-security/</link><pubDate>Sat, 20 Apr 2013 18:29:01 +0000</pubDate><guid>https://omid.dev/2013/04/20/java-8-release-schedule-delayed-for-renewed-focus-on-security/</guid><description>&lt;p&gt;&lt;a href="https://omid.dev/images/2013/04/Java.jpg"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2013/04/Java-150x150.jpg" alt="Java" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;ISC Handler &lt;a href="https://isc.sans.edu/handler_list.html#rob-vandenbrink"&gt;Rob V&lt;/a&gt; pointed out a blog post from Oracle&amp;rsquo;s &lt;a href="http://mreinhold.org/blog/"&gt;Mark Reinhold&lt;/a&gt; stating that Oracle has “mounted an intense effort to address those issues in a series of critical-patch update releases” and that they&amp;rsquo;ve also upgraded their “development processes to increase the level of scrutiny applied to new code, so that new code doesn’t introduce new vulnerabilities.”&lt;/p&gt;
&lt;p&gt;Framing statements state that Oracle:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;is committed to continue fixing security issues at an accelerated pace&lt;/li&gt;
&lt;li&gt;will enhance the Java security model&lt;/li&gt;
&lt;li&gt;will introduce new security features&lt;/li&gt;
&lt;li&gt;recoginizes that more engineer hours are required than can be freed up by dropping features from Java 8 or otherwise reducing the scope of the release at this stage&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As such, the likely release of Java 8 will be in the first quarter of 2014 (had been intended for September 2013).&lt;/p&gt;</description></item><item><title>Java zero day vulnerability actively used in targeted attacks</title><link>https://omid.dev/2012/08/27/java-zero-day-vulnerability-actively-used-in-targeted-attacks/</link><pubDate>Mon, 27 Aug 2012 19:50:00 +0000</pubDate><guid>https://omid.dev/2012/08/27/java-zero-day-vulnerability-actively-used-in-targeted-attacks/</guid><description>&lt;p&gt;&lt;a href="http://www.zdnet.com/java-zero-day-vulnerability-actively-used-in-targeted-attacks-7000003233/"&gt;&lt;img loading="lazy" src="http://lh4.ggpht.com/-Z71qqXKB38g/UDvIjUWvYyI/AAAAAAAAHPQ/S_hkki2ZjnU/Java%25255B9%25255D.jpg?imgmax=800" alt="Java" /&gt;
ZDNet&lt;/a&gt;: Security researchers from &lt;a href="http://blog.fireeye.com/research/2012/08/zero-day-season-is-not-over-yet.html"&gt;FireEye&lt;/a&gt;, &lt;a href="http://labs.alienvault.com/labs/index.php/2012/new-java-0day-exploited-in-the-wild/"&gt;AlienVault&lt;/a&gt;, and &lt;a href="http://www.deependresearch.org/2012/08/java-7-0-day-vulnerability-information.html"&gt;DeependResearch&lt;/a&gt; have intercepted targeted malware attacks utilizing the latest Java zero day exploit. The vulnerability affects Java 7 (1.7) Update 0 to 6. It does not affect Java 6 and below.&lt;/p&gt;
&lt;p&gt;Based on &lt;a href="https://community.rapid7.com/community/metasploit/blog/2012/08/27/lets-start-the-week-with-a-new-java-0day"&gt;related reports&lt;/a&gt;, researchers were able to reproduce the exploit on Windows 7 SP1 with Java 7 Update 6. There&amp;rsquo;s also &lt;a href="https://community.rapid7.com/community/metasploit/blog/2012/08/27/lets-start-the-week-with-a-new-java-0day"&gt;a Metasploit module&lt;/a&gt; available.&lt;/p&gt;
&lt;p&gt;Upon successful exploitation, the campaign drops &lt;a href="https://www.virustotal.com/file/09d10ae0f763e91982e1c276aad0b26a575840ad986b8f53553a4ea0a948200f/analysis/1346055031/"&gt;MD5: 4a55bf1448262bf71707eef7fc168f7d&lt;/a&gt; – detected by 28 out of 42 antivirus scanners as Gen:Trojan.Heur.FU.bqW@a4uT4@bb; Backdoor:Win32/Poison.E&lt;/p&gt;</description></item><item><title>Java 6 Update 27 released</title><link>https://omid.dev/2011/08/25/java-6-update-27-released/</link><pubDate>Thu, 25 Aug 2011 10:43:00 +0000</pubDate><guid>https://omid.dev/2011/08/25/java-6-update-27-released/</guid><description>&lt;p&gt;&lt;a href="https://omid.dev/images/2011/08/Java-77c57f9f.jpg"&gt;&lt;img loading="lazy" src="https://omid.dev/images/2011/08/Java.jpg" alt="" /&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Java™ SE 6 Update 27&lt;/strong&gt;&lt;br&gt;
The full internal version number for this update release is 1.6.0_27-b07 (where “b” means “build”). The external version number is 6u27.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Highlights&lt;/strong&gt;&lt;br&gt;
This update release contains important enhancements for Java applications:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Improved performance and stability&lt;/li&gt;
&lt;li&gt;Certification for Firefox 5&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Update release notes: &lt;a href="http://www.oracle.com/technetwork/java/javase/6u27-relnotes-444147.html"&gt;http://www.oracle.com/technetwork/java/javase/6u27-relnotes-444147.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Complete bug fix list: &lt;a href="http://www.oracle.com/technetwork/java/javase/2col/6u27bugfixes-444150.html"&gt;http://www.oracle.com/technetwork/java/javase/2col/6u27bugfixes-444150.html&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Java surpasses Adobe kit as most attacked software</title><link>https://omid.dev/2010/10/20/java-surpasses-adobe-kit-as-most-attacked-software/</link><pubDate>Wed, 20 Oct 2010 12:56:00 +0000</pubDate><guid>https://omid.dev/2010/10/20/java-surpasses-adobe-kit-as-most-attacked-software/</guid><description>&lt;p&gt;&lt;strong&gt;Researcher sees ‘unprecedented wave of Java exploitation&amp;rsquo;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh3.ggpht.com/_vaUVXcmC3OI/TL7f21tN5KI/AAAAAAAACyM/Dlv4DusDdXw/s1600-h/adobe-logo%5B2%5D.jpg" alt="adobe-logo%5B2%5D" /&gt;
&lt;/p&gt;
&lt;p&gt;&lt;img loading="lazy" src="http://lh5.ggpht.com/_vaUVXcmC3OI/TL7f6JUSFZI/AAAAAAAACyU/tLMWhhYGqSw/s1600-h/Java%5B2%5D.jpg" alt="Java" /&gt;
Oracle&amp;rsquo;s Java framework has surpassed Adobe applications as the most attacked software package, according to a Microsoft researcher who warned she was seeing “an unprecedented wave of Java exploitation.”&lt;/p&gt;
&lt;p&gt;The spike began in the third-quarter of last year and has climbed steadily since, according to data &lt;a href="http://blogs.technet.com/b/mmpc/archive/2010/10/18/have-you-checked-the-java.aspx"&gt;reported on Monday&lt;/a&gt; by Holly Stewart, a member of the Microsoft Malware Protection Center. By the beginning of this year, the number of Java exploits “had well surpassed the total number of Adobe-related exploits we monitored,” she said.&lt;/p&gt;</description></item></channel></rss>