Providing Free and Editor Tested Downloads

< HOME | MAC | GEEK - WEAR | SHOPPING | SUPPORT FORUM | TOP DOWNLOADS | >
MajorGeeks.com - We know you're out there, and we're coming to get you.

Admin Tools
All In One
Android
Anti-Spyware
Anti-Virus
Appearance
Back Up
Benchmarking
Bios
Browsers
CD\DVD\Blu-Ray
Covert Ops
Data Recovery
Diagnostics
Drive Cleaners
Drive Utilities
Driver Tools
Drivers
Ergonomics
Firewalls
Game Tweaks
Graphics
Input Device
Internet Tools
Mail Utilities
Memory
Messaging
Microsoft
Misc
Monitoring
Multimedia
Networking
Office Tools
ProcessManagement
Processor
Registry
Security
System Info
Toys
Video
Macintosh
Games
News Archive
- Off Base
- Way Off Base


· Jeskola Buzz Build 1486
· Google Chrome 27.0.1453.93 Stable
· Blender 2.67a
· VueScan 9.2.19
· AIDA64 Extreme Edition 2.85.2454 Beta
· WinGuard Pro 2013 8.9
· Video To Video Converter 2.9.5.0
· Spybot-Search & Destroy 2.1.19.0 Final
· RadioCast 1.0
· Speak-A-Message 9.1.0

· New? Start Here
· Top Freeware Picks
· Malware Removal
· Compatibility Database
· Geektionary
· Geek Shopping
· Free Magazines
· Useful Links
· Top Freeware Picks
· Folding@Home
· About Us
· Copyright
· Privacy
· Terms Of Service
· Uninstall

There are currently 2251 user(s) online:
Google, Live Search, Yahoo

YouTube

FaceBook

Twitter

RSS / XML Feed

Pintrest



Follow @majorgeeks
· Google · Yahoo · MSN


1. K-Lite Codec Pack Update
2. IObit SmartDefrag
3. Malwarebytes Anti-Malware
4. Win7codecs
5. IObit Malware Fighter
6. JetClean
7. x64 Components
8. SpywareBlaster
9. Windows 8 Codecs
10. Advanced SystemCare Free 6.2.0.254 (0424)
More >>

The plane! The plane! Fantasy Island airplane used to smuggle drugs after show finished (Video)

What's The Best Browser to Protect You against Malware?

Friday Photo Bombs!

Female fan who flipped off Noah in photo identified as Filomena Tobias

Majorgeeks updates website to new CMS and design – didn’t break EVERYTHING

First time setup and installation of an SSD drive

Friday Photo Bombs!

NASA dumping Windows for Linux

World Of Warcraft loses 1.3 million subscribers in 3 months

Pay attention to the Kiss Cam (Video)





MajorGeeks.com » News » August 2012 » Oracle Releases Fix For Java Flaw

Oracle Releases Fix For Java Flaw


Posted on: 08/30/2012 05:02 PM [ Comments ]


Oracle on Thursday released a new version of Java that included a fix for the CVE-2012-4681 vulnerability that has been used in limited targeted attacks in the last couple of weeks. The release of Java 7 update 7 comes about four days after the Java flaw was publicly disclosed, but several months after researchers say they notified Oracle of the problem.

Oracle didn't release a security advisory or acknowledge the vulnerability until releasing the new version, along with some release notes today. Security researchers say that the new version of Java prevents existing exploit code from working. Attackers have been using the Java vulnerability, which actually comprises two separate bugs, in attacks since at least early last week and many of the attacks have resulted in the installation of the Poison Ivy RAT, giving the attackers remote access to the machines.

The release notes for the Java 7 update contain a reference to the CVE-2012-4681 vulnerability and says that it's fixed in the new version.

"These vulnerabilities may be remotely exploitable without authentication, i.e., they may be exploited over a network without the need for a username and password. To be successfully exploited, an unsuspecting user running an affected release in a browser will need to visit a malicious web page that leverages this vulnerability. Successful exploits can impact the availability, integrity, and confidentiality of the user's system," Oracle's security advisory said.

"Due to the severity of these vulnerabilities, the public disclosure of technical details and the reported exploitation of CVE-2012-4681 'in the wild,' Oracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible."

Researchers at Polish firm Security Explorations said this week that they disclosed the two Java flaws in CVE-2012-4681 to Oracle about four months ago, but no patch was forthcoming until this week.

When the vulnerabilities became public knowledge on Sunday, researchers said that there already were targeted attacks exploiting the bugs. The early attacks have been traced to China and researchers found that one of the groups using the bugs was behind the so-called Nitro attacks against chemical companies and defense contractors last year. The group is using the same command-and-control infrastructure in the new wave of attacks.








Like it? Share it....




Comments
comments powered by Disqus

« Purdue Students Use Xbox Kinect to Make 3D Objects Using Natural Hand Movements · Oracle Releases Fix For Java Flaw · CompatDB Updates 08/31/12 »

MajorGeeks.com » News » August 2012 » Oracle Releases Fix For Java Flaw
© 2000-2013 MajorGeeks.com
Powered by Contentteller® Business Edition