| Windows 7: Oracle issues major Java security fix; recommends immediate action |
30 Aug 2012
|
| | 64-bit Windows 7 Ultimate SP1 & Windows 8 Enterprise 47,724 posts Texas |
Oracle issues major Java security fix; recommends immediate action Quote: Oracle has just released an update that is intended to patch up three "distinct but related vulnerabilities" as well as another serious security issue regarding Java running on desktop browsers.
More specifically, the security holes could be exploited over a network without needing a username and password if an unsuspecting user is running an affected release in a browser and then visits a malicious web page that leverages this vulnerability.
The possible outcome is that the vulnerabilities could be used to exploit personal data and accessibility of the user's system overall.
Oracle software security assurance director Eric Maurice explained in a blog post on Thursday that customers should apply the updates as soon as possible because many of the technical details related to the vulnerabilities are already widely available online.
Read more at source: Oracle issues major Java security fix; recommends immediate action | ZDNet | My System Specs |
| Computer type PC/Desktop System Manufacturer/Model Number Self built custom OS 64-bit Windows 7 Ultimate SP1 & Windows 8 Enterprise CPU Intel i7-3930K 3.2 Ghz (O/C 4 Ghz) Motherboard ASRock X79 Extreme11 Memory 32 GB (8GBx4) G.SKILL DDR3 Quad PC3-19200 2400MHz Graphics Card Sapphire HD5870 Eyefinity 6 2GB Sound Card SB Recon 3Di Integrated Chip Monitor(s) Displays 3x 27" Asus VE278Q Screen Resolution 1920x1080 Keyboard Logitech Cordless Desktop MX 5500 Revolution Mouse Logitech Cordless Desktop MX 5500 Revolution PSU OCZ Series Gold OCZZ1000M 1000W Case Thermaltake Level 10 GT Snow Edition Cooling Corsair Hydro H100 Hard Drives 256GB OCZ Vector
160GB OCZ RevoDrive X2
2 x 1TB Samsung HDD HD154UI SATA Internet Speed 50 Mb/s Download and 2 Mb/s Upload Other Info Microsoft LifeCam Cinema
Lite-On iHBS212 12x BD Writer
Samsung CLX-3175FW Printer
Netgear WNDR3800 Router
Motorola SBG6580 Cable Modem
2x APC Back-UPS XS 1500 |
30 Aug 2012
|
| | Windows 7 Professional x64, SP1 157 posts New Zealand |
Many thanks Brink. I have been following this with interest and can now go out to my customers and advise issue resolved and to update immediately. | My System Specs | | System Manufacturer/Model Number HP Pavilion p6040a OS Windows 7 Professional x64, SP1 CPU Intel Core 2 Duo E7400 2.8GHz Motherboard FOXCONN Napa Memory 4GB Graphics Card ATI Radeon HD3540 |
30 Aug 2012
|
| | Windows 7 Home Premium 64bit 593 posts Walnut Beach,Milford,CT |
Is there any problem with disabling Java ?
Such as: Java console, Deployment tool kit, or Platform SE 6 U33.
Can I safely delete these ?
Last edited by COMPUTIAC; 31 Aug 2012 at 06:57 PM..
| My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Self - built OS Windows 7 Home Premium 64bit CPU AMD FX-8350 8 core Motherboard ASUS M5A99X EVO R2.0 Memory 16GB / Corsair XMS3 Graphics Card MSI GeForce GTX 650 Ti Boost Sound Card on-board Monitor(s) Displays HP 2311x Screen Resolution 1920x1080 Keyboard Logitech Illuminated Mouse M$ - Arc Touch PSU Ultra X4 modular 1050w Case Fractal Define R4 Cooling Cooler Master Gemin II S524 - CPU Cooler Hard Drives SSD: OCZ Vertex 3/120GB;(OS,programs)
HDD's; SAMSUNG EcoGreen F4 2 Tb internal(for Data)
Hitachi, 1Tb external,(B'up) Internet Speed 21Mb down / 2Mb up Antivirus Avast 8 Internet Security, MBAM Pro, SAS Pro Browser Firefox (newest) Other Info Cisco E-3000 router, Logitech Z506, 5.1 speakers. |
31 Aug 2012
|
| | Windows 7 Ultimate X64 SP1 13,813 posts Mt. Crumpit/Whoville |
A test for your Java's vulnerability. Is Java Exploitable? powered by Rapid7 | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Home Built Desktop By DataTech OS Windows 7 Ultimate X64 SP1 CPU Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU Motherboard ASUS P8Z68-V PRO/GEN3 Memory 16GB G.Skill Sniper 2133MHz 4x4GB Graphics Card ASUS ENGTX460 DirectCU/2DI/1GD5 GeForce GTX 460 Sound Card Onboard Realtek 5-1 Monitor(s) Displays Samsung P2570HD Screen Resolution 1920x1080 Keyboard Old, beat-up Dell USB From 10 yrs Ago Mouse Gigabyte m6900 wired PSU Corsair HX650W Case Inwin Dragon Rider Cooling Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM Hard Drives Crucial M4 128GB for OS, 750GB Seagate MomentusXT for data, 500GB Seagate Constellation for storage Internet Speed 8-19 Mbs down, 3-4 Mbs up Comcast Cable Antivirus Norton Internet Security Browser IE 9, Opera when needed Other Info 4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power generator with flux capacitor, 1.21 gigawatts. |
31 Aug 2012
|
| | Windows 7 Home Premium 32bit 74 posts |
Let's see now. The first version of Java was to save the world from ever having to rewrite a program in any other language or for any platform - as in "write once, run everywhere." Did it do that? No! Did it help? Maybe but maybe not.
There was also supposed to be no risk of attack because Java was "safe" and executed in it's own protected environment. Was it? How about the n updates to correct bugs and exploit weak points where n is a continually increasing number. However, now that these last few attack points have been fixed, it is totally and absolutely safe. Oh sure, we can believe that since that is EXACTLY what they said for EACH of the n-1 last upgrades can't we? I don't think we can trust it. At least I don't.
You don't create quality software by running a customer based world wide alpha test. You do it by designing and building the quality into the product BEFORE you release the software. Clearly, this was not done for the Oracle version of Java. There has been countless "updates". Because of that, we have every reason to believe there are uncounted and undiscovered bugs and exploit points living and likely reproducing inside the Java engine. There is also every reason to believe that every bug fix will insert one or more new bugs - likely more.
The bottom line appears to me that Java itself IS the problem. It is a Trojan, a virus, a worm, and social hacking rolled into one package. Was this done on purpose, by incompetency, or carelessness? It doesn't matter. They all have the same result. Java is dangerous to your system and data health because of its design, implementation, and inadequate up front quality control.
Use it at your own risk. I, for one will NOT use it for any purpose.
Have a nice day. | My System Specs | | OS Windows 7 Home Premium 32bit |
31 Aug 2012
|
| | Windows 7 Home Premium SP1, clean install, upgrade disc 15,045 posts CT |
The latest security fix for Java can be breached.
I have taken the warnings seriously and have uninstalled Java. Most computer users need Java only on rare ocassions. Researchers Find Critical Vulnerability in Java 7 Patch Hours After Release | PCWorld Business Center | My System Specs | | System Manufacturer/Model Number Dell XPS 420 OS Windows 7 Home Premium SP1, clean install, upgrade disc CPU Intel Core2 processsor Q8200(2.33Ghz 1333FSB) Quad Core Tech Motherboard Dell Memory 6 gb Graphics Card ATI Radeon 256MB HD3650 Sound Card Intergrated 7.1 Channel Audio Monitor(s) Displays Dell SP2009W 20" Keyboard Dell USB Keyboard Mouse Dell Premium Optical USB Cooling Fan Hard Drives 640 GB Serial ATA Hard drive Internet Speed DSL 2.85 |
01 Sep 2012
|
| | Windows 7 Ultimate X64 SP1 13,813 posts Mt. Crumpit/Whoville |
I never installed Java with my new install and don't miss it.
Perhaps Oracle should contact these security firms for help in issuing patches. They seem to find an exploit with each Java update. | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Home Built Desktop By DataTech OS Windows 7 Ultimate X64 SP1 CPU Intel i5-2550K, Differing ~4.4-4.8GHz No built in GPU Motherboard ASUS P8Z68-V PRO/GEN3 Memory 16GB G.Skill Sniper 2133MHz 4x4GB Graphics Card ASUS ENGTX460 DirectCU/2DI/1GD5 GeForce GTX 460 Sound Card Onboard Realtek 5-1 Monitor(s) Displays Samsung P2570HD Screen Resolution 1920x1080 Keyboard Old, beat-up Dell USB From 10 yrs Ago Mouse Gigabyte m6900 wired PSU Corsair HX650W Case Inwin Dragon Rider Cooling Hyper 212 EVO w/two Noctua fans, push-pull, @1300 RPM Hard Drives Crucial M4 128GB for OS, 750GB Seagate MomentusXT for data, 500GB Seagate Constellation for storage Internet Speed 8-19 Mbs down, 3-4 Mbs up Comcast Cable Antivirus Norton Internet Security Browser IE 9, Opera when needed Other Info 4 case fans, LG BluRay-RE, ASUS DVD-RW, Mr. Fusion power generator with flux capacitor, 1.21 gigawatts. |
01 Sep 2012
|
| | Windows 7 Home Premium x86 Service Pack 1 - Linux Mint Mate 14 x64 4,495 posts Milton Keynes |
So, I've just gone installed Update 7 for Java 7 yesterday, believing that all the security issues have been resolved, and now more security problems have been found?
I use Java most of the time.
Last edited by x BlueRobot; 01 Sep 2012 at 07:33 AM..
| My System Specs | | Computer type Laptop System Manufacturer/Model Number HP Pavilion dm1 Notebook PC OS Windows 7 Home Premium x86 Service Pack 1 - Linux Mint Mate 14 x64 CPU AMD E-450 APU (64-Bit) @ 1.65GHz Dual-Core Motherboard HP 3387 36.0A (Socket FT1) Memory 4GB DDR3 @ 676MHz Graphics Card AMD Radeon HD 6320 Graphics Sound Card Beats Audio - IDT High Definition Audio CODEC Monitor(s) Displays LCD HP Monitor Screen Resolution 1366 x 768 @ 60Hz Keyboard Standard PS/2 Keyboard Mouse Synaptics TouchPad V 7.5/Logitech USB Wireless PSU Microsoft Composite Battery - ACPI Case HP Cooling HP Cool Sense Hard Drives 500GB - SATA Hitachi HTS547550A9E384 Internet Speed 24.0 Mbps Antivirus Microsoft Security Essentials Browser Opera 12.15; Firefox 21 Other Info NIC - Broadcom 4313GN 802.11b/g/n Wi-Fi Adapter
Belkin Black Laptop Cooling Stand Oracle issues major Java security fix; recommends immediate action problems? All times are GMT -5. The time now is 01:05 PM. | |