Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Serious software for the not so serious geek.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. MusicBee
8. Rufus
9. K-Lite Mega Codec Pack
10. Sergei Strelec's WinPE
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » January 2013 » Fix for critical Java hole released

Fix for critical Java hole released


Contributed by: Email on 01/14/2013 03:03 PM [ comments Comments ]


Oracle has released Java 7 Update 11, which includes a fix for the critical vulnerability disclosed at the beginning of January that has already been widely exploited. The update also includes a fix for another previously undisclosed critical vulnerability. Oracle also confirmed that the flaws in question do not affect Java 6 or earlier versions of the runtime. Oracle urges users to update as soon as possible.

The security alert for CVE-2013-0422 notes in its Risk Matrix that CVE-2012-3174, another critical, remotely exploitable vulnerability, is also being fixed in the update. Little is known of the equally severe vulnerability except that its CVE number was apparently assigned in June 2011 and its discovery appears to be credited to a Brian Murphy via TippingPoint.

The Java 7 update also changes the default security policy of the Java plugin so that, from now on, unsigned applets will always generate a warning to the user before being run. This should reduce the ability of attackers to exploit Java applet support in drive-by malware attacks which rely on the plugin executing the malicious code silently. The "click-to-play" behavior is similar to the precautions that Mozilla took with Firefox. The defensive measures Apple took, blocking the specific version of Java, will mean that when the update is installed, the Java plugin will resume operation.

Despite Oracle's speedier response closing the new holes with a reminder in the release notes to re-enable the Java plugin if disabled, the consensus amongst security experts is to leave Java disabled in the browser especially as few sites use Java. The Windows control panel for Java also allows users to easily disable the Java plugin. Instructions on how to disable Java in Chrome, Firefox and Safari are also available.






« ICS-CERT reports virus infections at US power utilities · Fix for critical Java hole released · Mob Underboss Anthony Zerilli Says Hoffa Left In Shallow Grave »




Comments
comments powered by Disqus

MajorGeeks.Com » News » January 2013 » Fix for critical Java hole released

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition