Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security

September 11th, 2012, 07:41 GMT · By

Security Explorations: Oracle Confirms Newly Discovered Java Vulnerability

SHARE:

Adjust text size:

Oracle has confirmed the existence of the second Java bug
Enlarge picture
Adam Gowdiak, the CEO of Security Explorations – the company that discovered the recent Java vulnerabilities -, told Softpedia that Oracle confirmed the existence of the second flaw, reported on August 31, 2012.

“Oracle confirmed the security issue reported to them on Aug 31, the one that affects the out-of-band patch released on Aug 30. This is visible at our vendor status page,” Gowdiak wrote in an email.

The second bug reported to Oracle was identified right after the company released an out-of-band patch for Java 7. Although it was unusual for them to make available such fixes, the move was necessary considering the fact that the vulnerability was exploited in the wild.

“The out-of-band patch released by Oracle yesterday, among other things fixed the exploitation vector with the use of SunToolkit class, the one we used in our proof of concept codes. This made many of them not working...Till today,” Gowdiak told us on August 31.

“When combined with some of the Apr 2012 issues, the new issue (number 32) reported to Oracle today allows to achieve a complete JVM sandbox bypass in the environment of latest Java SE 7 Update 7 (version that was released on Aug 30, 2012),” he added.

He warned that the newly discovered bug meant that users were still at risk.

Oracle has confirmed that these newly discovered issues will be addressed in the upcoming CPU (the one that will be launched in October).

In the meantime, users are advised to disable their Java Runtime Environment browser plugins, or remove the component altogether if it’s not needed for everyday tasks.

Alternatively, internauts can keep Java installed only in one of their browsers - the one they utilize for work-related operations -, ensuring that the one used for surfing the Web hasn’t got the software activated.


2,328 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Java Users Still Not Safe, Experts Report New Vulnerability to Oracle (Exclusive)

Security Explorations: Oracle Has Already Prepared the Fix for Java Zero-Day

Mozilla Issues Java Block and Notifications for Firefox

Oracle Fixes Java Zero-Day Flaw, Users Advised to Download Patch

Apple Patches Zero-Day Vulnerability in OS X

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM