Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - No Geek, no glory.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. Smart Defrag
2. GS Auto Clicker
3. Macrium Reflect FREE Edition
4. Sergei Strelec's WinPE
5. MusicBee
6. Visual C++ Redistributable Runtimes AIO Repack
7. K-Lite Mega Codec Pack
8. ImgBurn
9. Unlocker
10. Format Factory
More >>

top reads

Star 8 Windows Shortcuts That’ll Make You More Productive and Save You Time

Star Windows 10 Not Dead Yet - You Can Still Get Updates For Free

Star What is a '400 Bad Request - Request Header or Cookie Too Large' Error and How to Fix It

Star How to Fix Windows Install Error 0xC1900101

Star How to Force Enable Windows 10 Extended Security Updates If The Option Is Not Showing

Star Windows 11 25H2 is Out: What’s New and How to Get It Now.

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star Boost Your PC Speed with ReadyBoost: How a Thumb Drive Can Enhance Your System's Performance

Star 5 Hidden Windows Tools You’ve Had All Along But Never Use

Star Use the Windows 10 Media Creation Tool Before Support Ends For Windows 10 in 2025


MajorGeeks.Com » News » January 2013 » Fix for critical Java hole released

Fix for critical Java hole released


Contributed by: Email on 01/14/2013 03:03 PM [ comments Comments ]


Oracle has released Java 7 Update 11, which includes a fix for the critical vulnerability disclosed at the beginning of January that has already been widely exploited. The update also includes a fix for another previously undisclosed critical vulnerability. Oracle also confirmed that the flaws in question do not affect Java 6 or earlier versions of the runtime. Oracle urges users to update as soon as possible.

The security alert for CVE-2013-0422 notes in its Risk Matrix that CVE-2012-3174, another critical, remotely exploitable vulnerability, is also being fixed in the update. Little is known of the equally severe vulnerability except that its CVE number was apparently assigned in June 2011 and its discovery appears to be credited to a Brian Murphy via TippingPoint.

The Java 7 update also changes the default security policy of the Java plugin so that, from now on, unsigned applets will always generate a warning to the user before being run. This should reduce the ability of attackers to exploit Java applet support in drive-by malware attacks which rely on the plugin executing the malicious code silently. The "click-to-play" behavior is similar to the precautions that Mozilla took with Firefox. The defensive measures Apple took, blocking the specific version of Java, will mean that when the update is installed, the Java plugin will resume operation.

Despite Oracle's speedier response closing the new holes with a reminder in the release notes to re-enable the Java plugin if disabled, the consensus amongst security experts is to leave Java disabled in the browser especially as few sites use Java. The Windows control panel for Java also allows users to easily disable the Java plugin. Instructions on how to disable Java in Chrome, Firefox and Safari are also available.






« ICS-CERT reports virus infections at US power utilities · Fix for critical Java hole released · Mob Underboss Anthony Zerilli Says Hoffa Left In Shallow Grave »




Comments
comments powered by Disqus

MajorGeeks.Com » News » January 2013 » Fix for critical Java hole released

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition