Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Get your Geek on.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews



IObit Black Friday Sale

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. MusicBee
5. Microsoft Visual C++ 2015-2022 Redistributable Package
6. Sergei Strelec's WinPE
7. Visual C++ Redistributable Runtimes AIO Repack
8. Mozilla Firefox
9. K-Lite Mega Codec Pack
10. Winslop
More >>

top reads

Star How To Remove the Windows 11 Updated Start Menu

Star How To Disable Drag Tray

Star How To Permanently Delete Files Without Sending Them to the Recycle Bin in Windows 11

Star How To Repair Install Windows 11, and Keep All Your Files and Apps

Star How To Turn Off Folder Backup Syncing on OneDrive

Star AI Actions - What Are They and How To Enable/Disable Them

Star Microsoft Is Ending 3rd Party Printer Driver Support in 2026: How to Protect Old Printer Drivers

Star How To Stop Edge and Chrome Default Browser Prompts

Star How To Configure Allowed Apps for Controlled Folder Access

Star Pause or Disable Automatic App Updates in Microsoft Store


MajorGeeks.Com » News » January 2013 » Fix for critical Java hole released

Fix for critical Java hole released


Contributed by: Email on 01/14/2013 03:03 PM [ comments Comments ]


Oracle has released Java 7 Update 11, which includes a fix for the critical vulnerability disclosed at the beginning of January that has already been widely exploited. The update also includes a fix for another previously undisclosed critical vulnerability. Oracle also confirmed that the flaws in question do not affect Java 6 or earlier versions of the runtime. Oracle urges users to update as soon as possible.

The security alert for CVE-2013-0422 notes in its Risk Matrix that CVE-2012-3174, another critical, remotely exploitable vulnerability, is also being fixed in the update. Little is known of the equally severe vulnerability except that its CVE number was apparently assigned in June 2011 and its discovery appears to be credited to a Brian Murphy via TippingPoint.

The Java 7 update also changes the default security policy of the Java plugin so that, from now on, unsigned applets will always generate a warning to the user before being run. This should reduce the ability of attackers to exploit Java applet support in drive-by malware attacks which rely on the plugin executing the malicious code silently. The "click-to-play" behavior is similar to the precautions that Mozilla took with Firefox. The defensive measures Apple took, blocking the specific version of Java, will mean that when the update is installed, the Java plugin will resume operation.

Despite Oracle's speedier response closing the new holes with a reminder in the release notes to re-enable the Java plugin if disabled, the consensus amongst security experts is to leave Java disabled in the browser especially as few sites use Java. The Windows control panel for Java also allows users to easily disable the Java plugin. Instructions on how to disable Java in Chrome, Firefox and Safari are also available.






« ICS-CERT reports virus infections at US power utilities · Fix for critical Java hole released · Mob Underboss Anthony Zerilli Says Hoffa Left In Shallow Grave »




Comments
comments powered by Disqus

MajorGeeks.Com » News » January 2013 » Fix for critical Java hole released

© 2000-2026 MajorGeeks.com
Powered by Contentteller® Business Edition