Language Selection

English French German Italian Portuguese Spanish

Java flaws open door to hackers

Filed under

The flaws are "highly critical," security monitoring company Secunia said in an advisory posted Tuesday. Flaws that get that ranking--one notch below Secunia's most severe "extremely critical" rating--are typically remotely exploitable and can lead to full system compromise.

Both flaws affect the Java Runtime Environment, or JRE. This is the Java software many computer users have on their system to run Java applications. The bugs could allow a Java application to read and write files or execute applications on a victim's computer, Sun said in two separate security advisories released Monday.

One is a general flaw in the JRE, while the other is specific to Java Web Start, a technology to load Java applications over a network such as the Internet.

The flaws could be exploited through a malicious Web site, according to alerts from the French Security Incident Response Team, which rates both issues "critical."

JRE is part of Sun's Java 2 Platform Standard Edition, or J2SE. Both flaws affect J2SE 5.0 and 5.0 Update 1 for Windows, Solaris and Linux. The general JRE flaw also affects J2SE 1.4.2_07 and earlier 1.4.2 releases for those operating systems, Sun said.

The Santa Clara, Calif.-based company is urging people to install updated software to protect against possible exploitation of the security flaws. It has released two software updates to address the issues: J2SE 5.0 Update 2, which has actually been available since February, and J2SE 1.4.2_08, which was released recently, company representatives said. The software can be downloaded from the Web site.

Sun said it wasn't aware of any exploits or attacks using the flaws.


More in Tux Machines

GNOME 3.20 Desktop Environment Gets Closer with the Latest Development Milestone

After a couple of weeks of hard work, and with a two-day delay, the second development milestone of the upcoming GNOME 3.20 desktop environment is finally here, available for testing on various GNU/Linux operating systems. Read more

Wine Announcement

The Wine development release 1.8-rc2 is now available. What's new in this release (see below for details): - Bug fixes only, we are in code freeze. The source is available from the following locations: Binary packages for various distributions will be available from: Read more

GNOME 3.19.2 released

Hi! The second snapshot of GNOME 3.19 is now available, it incorporates updates from 3.18.2 as well as quite a serie of edgier modules. To compile GNOME 3.19.2, you can use the jhbuild [1] modulesets [2] (which use the exact tarball versions from the official release). [1] [2] Read more