Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - No Geek, no glory.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews



IObit Black Friday Sale

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Mozilla Firefox
4. Smart Defrag
5. MusicBee
6. Microsoft Visual C++ 2015-2022 Redistributable Package
7. Sergei Strelec's WinPE
8. Visual C++ Redistributable Runtimes AIO Repack
9. Dolby AC-3/AC-4 Installer
10. McAfee Removal Tool (MCPR)
More >>

top reads

Star Lossless vs Lossy: When FLAC, APE, and ALAC Beat MP3 and When They Don't

Star Google Search Tricks You'll Actually Use in 2025 and Beyond

Star Fresh PC Checklist: First 12 Things to Do On a New Windows 11 Machine

Star Running AI Models Locally: What They Are, Where to Find Them, and How to Get Started

Star Deciding Between Idle State, Sleep Mode, and Shutdown: What's Best for Your PC?

Star How to Fix VMware Workstation "The Update Server Could Not Be Resolved" Error Installing VMware Tools

Star How to Remove Google Gemini from Your Phone (and Your Life)

Star Windows Bloat Removal Guide: Debloat Safely and Keep What You Need

Star Windows 11 Repair Playbook: SFC, DISM, CHKDSK Without Breaking Stuff

Star Gmail Using Your Emails and Attachments for AI Training: Here's How To Opt Out


MajorGeeks.Com » News » February 2013 » New holes discovered in latest Java versions

New holes discovered in latest Java versions


Contributed by: Email on 02/26/2013 04:05 PM [ comments Comments ]


Security Explorations has informed Oracle of two new vulnerabilities in Java, "issue 54" and "issue 55", which it says can be combined to completely bypass Java's sandbox security. Adam Gowdiak, researcher at Security Explorations, told Softpedia that the problems are specific to Java 7 SE versions, and allow abuse of the Reflection API in Java, "in a particularly interesting way".

Gowdiak has tested the flaws on the original Java SE 7 release, Java SE 7 Update 11, and the recently released Java SE 7 Update 15. According to Security Exploration's bug status page, Oracle has acknowledged that it has received the vulnerability details and proof of concept code and says it will investigate and get back to the company soon. The page also notes that a previous flaw, "issue 51", is still under investigation after being reported in mid-January.

Java security flaws have been making the headlines recently, especially after companies including Twitter, Apple, Microsoft and Facebook found attackers had, using Java flaws, hijacked iPhoneDevSDK forums to deliver malware to employee laptops. Oracle has been releasing updates to Java, including Java 7 Update 13, a 50 vulnerability patch pack at the start of February. But, as with all updates, they take time to apply and this opens a window of opportunity for attackers. Rapid 7 is reporting, for example, that an exploit for Java 7 Update 11 which was only released in mid January, is being used in the wild and has been integrated with a number of exploit kits. This makes it more important than ever to ensure that Java is up to date.

The other option is to disable Java in the browser. The H advises users who do not need Java in their browser to disable the Java plugin to help ensure their safety. The most recent Java updates include a switch in the Java Control Panel on Windows to disable Java in the browser.






« Google's two-factor authentication bypassed · New holes discovered in latest Java versions · HP shifting resources from PCs to tablets »




Comments
comments powered by Disqus

MajorGeeks.Com » News » February 2013 » New holes discovered in latest Java versions

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition