JSchlackman Posted March 4, 2013 Posted March 4, 2013 Well, we all knew it was coming. Security Alert CVE-2013-1493 - update here. This Security Alert contains 2 new security fixes for Oracle Java SE. Both of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password. By my count that's the 4th one this year. I have a tenner that says we'll make 5 by Easter.
SYNACK Posted March 5, 2013 Posted March 5, 2013 Just came here to post a rant about this, if only I could get rid of it my days could be filled with betterment rather than fighting with the primative sack of ...
vikpaw Posted March 5, 2013 Posted March 5, 2013 I've given up with Java Ben At least they are admitting the problem now: 2
free780 Posted March 5, 2013 Posted March 5, 2013 Id really like to whitelist java to only the local intranet. Any ideas? The best i can do is get IE to prompt with the yellow bar for non approved domains.
AngryTechnician Posted March 5, 2013 Posted March 5, 2013 You could configure a deployment.properties file with bogus proxy settings, that way it wouldn't connect to anything outside your network.
Arthur Posted April 9, 2013 Posted April 9, 2013 At least they are admitting the problem now: Only 2.85 billion devices at risk now!!! Java-based attacks remain at large, researchers say « ZDNet The researchers found that the latest version of Java, version 1.7.17, is only in use by a dismal five percent of users, and many versions are months or years out of date — just begging to be exploited. http://i.imgur.com/KREcJnB.png The most widely-detected version of Java currently in use is version 1.6.16. Over 75 percent of browsers are using Java versions which are at least 6 months old, whereas nearly two-thirds are a year out of date, and 50 percent of Java versions in use are over two years behind the times in respect to Java vulnerabilities. All in all, the researchers say that the vulnerable population of browsers is pegged at a staggering 93.77 percent.
sted Posted April 10, 2013 Posted April 10, 2013 Only 2.85 billion devices at risk now!!! Java-based attacks remain at large, researchers say « ZDNet what do they expect when by the time youve found theres an update and tested it theres another one. they would do better actually testing it then releasing updates every few months not days same as flash
JSchlackman Posted April 15, 2013 Author Posted April 15, 2013 Well, I would have lost my tenner, but I was close: another Java 7 update is due out on Tuesday. Ars Technica are reporting that it is Java 7 Update 21, but don't explain what happened to update 18, 19 and 20 (update 17 is the latest one available for download). So technically maybe I was right? Who even knows any more.
Arthur Posted April 15, 2013 Posted April 15, 2013 another Java 7 update is due out on Tuesday A few more dates for your diary... For Oracle Java SE Critical Patch Updates, the next scheduled dates are: 16 April 2013 18 June 2013 15 October 2013 14 January 2014
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now