![]() |
|
|||||||
| News News regarding BSD and related. |
![]() |
|
|
Thread Tools | Display Modes |
|
|
|
||||
|
This effects all versions of Oracle Java (JRE 1.7 Update 10 and earlier), including both the JRE and JRE browser plugins.
From US DHS CERT: Quote:
__________________
OpenBSD LiveCDs/LiveDVDs |
|
|||
|
Why is it called "In the wild"?
Are there a bunch of crazed woodland creatures passing away their time hacking and not hibernating? Serious side: Java has been and is known for running on most architectures and being able to affect them. An exploit on a SPARC64 machine can be used to control i386 clients. Did the particular developer of the code in question test it for vulnerabilities? Sometimes there should be more people like deRaadt when it comes to code.
__________________
No signature |
|
||||
|
Oracle issued an emergency update over the weekend (JRE 7 Update 11) which some reports have called insufficient. Here's an in-depth article.
__________________
OpenBSD LiveCDs/LiveDVDs |
|
|||
|
From another site : http://www.networkworld.com/communit...ke-2-years-fix
Quote:
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump |
|
||||
|
To be clear, the security flaw affects JRE as well as the JRE plugin; the press is focused on the plugin but if I understand the problem there is still a risk with JRE (non-plugin) if it is used as a Client in a Client/Server HTML application.
__________________
OpenBSD LiveCDs/LiveDVDs |
|
|||
|
According to Another Java zero-day vulnerability apparently available the problems with Java are still not over ....
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump |
|
|||
|
The problem with Java is so apparent that one of my friends who is not into computers/OSes/architectures as I am had mentioned it.
__________________
No signature |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Security Oracle releases emergency fixes for Java 0day exploit | J65nko | News | 0 | 30th August 2012 10:19 PM |
| Security New Adobe Reader zero-day in the wild | J65nko | News | 1 | 8th December 2011 07:22 PM |
| Dev goes 'Wild' with H.264 Firefox | J65nko | News | 0 | 19th May 2010 09:43 PM |
| Zero day exploit for Firefox 3.6 | J65nko | News | 1 | 19th February 2010 05:58 PM |
| vbox: possible exploit | Mr-Biscuit | Other BSD and UNIX/UNIX-like | 9 | 18th October 2008 06:33 PM |