JDK 1.7.0_11 is out.

R

Roedy Green

Presumably will fix the 0-day exploit.
I will find out after I get it myself.

the release notes are at
http://www.oracle.com/technetwork/java/javase/7u11-relnotes-1896856.html

As I read them the "fix" is just to turn off Applets entirely, by
default -- hardly a fix. Perhaps one of the group's language lawyers
could see if I interpreted that correctly.
--
Roedy Green Canadian Mind Products http://mindprod.com
The first 90% of the code accounts for the first 90% of the development time.
The remaining 10% of the code accounts for the other 90% of the development
time.
~ Tom Cargill Ninety-ninety Law
 
A

Arne Vajhøj

the release notes are at
http://www.oracle.com/technetwork/java/javase/7u11-relnotes-1896856.html

As I read them the "fix" is just to turn off Applets entirely, by
default -- hardly a fix. Perhaps one of the group's language lawyers
could see if I interpreted that correctly.

I don't read it that way.

<quote>
This release contains fixes for security vulnerabilities. For more
information, see Oracle Security Alert for CVE-2013-0422.

In addition, the following change has been made:

Area: deploy
Synopsis: Default Security Level Setting Changed to High
The default security level for Java applets and web start applications
has been increased from "Medium" to "High".
</quote>

.... contains fixes ... in addition ... security level
setting changed ...

I can not interpret that other than there are both a fix
and a change in default security level.

Arne
 
E

Eric Sosman

[...]
<quote>
This release contains fixes for security vulnerabilities. For more
information, see Oracle Security Alert for CVE-2013-0422.

CERT's advice is

"Immunity has indicated that only the reflection
vulnerability has been fixed and that the JMX MBean
vulnerability remains. [...] Unless it is absolutely
necessary to run Java in web browsers, disable it as
described below, even after updating to 7u11. [...]"
--from <http://www.kb.cert.org/vuls/id/625617>

Write once, pwn anywhere ...
 
A

Arne Vajhøj

[...]
<quote>
This release contains fixes for security vulnerabilities. For more
information, see Oracle Security Alert for CVE-2013-0422.

CERT's advice is

"Immunity has indicated that only the reflection
vulnerability has been fixed and that the JMX MBean
vulnerability remains. [...] Unless it is absolutely
necessary to run Java in web browsers, disable it as
described below, even after updating to 7u11. [...]"
--from <http://www.kb.cert.org/vuls/id/625617>

Write once, pwn anywhere ...

According to the link then the exploits require both
vulnerabilities.

But obviously the unfixed problem could be part of new
exploits as well.

So it definitely should be fixed. And hopefully it
will be.

Arne
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

JDK 1.7.0_60 is out 1
jdk 1.7.0_13 is out 4
JDK 1.7.0_15 is out 2
Just starting out 1
JDK 1.7.0_05 is out 1
Where is JDK 1.7_15 going on Mac 18
I'm tempted to quit out of frustration 1
JDK 1.6.0_25 is out 2

Members online

No members online now.

Forum statistics

Threads
473,755
Messages
2,569,537
Members
45,020
Latest member
GenesisGai

Latest Threads

Top