Language Selection

English French German Italian Portuguese Spanish

Java flaws open door to hackers

Filed under
Security

The flaws are "highly critical," security monitoring company Secunia said in an advisory posted Tuesday. Flaws that get that ranking--one notch below Secunia's most severe "extremely critical" rating--are typically remotely exploitable and can lead to full system compromise.

Both flaws affect the Java Runtime Environment, or JRE. This is the Java software many computer users have on their system to run Java applications. The bugs could allow a Java application to read and write files or execute applications on a victim's computer, Sun said in two separate security advisories released Monday.

One is a general flaw in the JRE, while the other is specific to Java Web Start, a technology to load Java applications over a network such as the Internet.

The flaws could be exploited through a malicious Web site, according to alerts from the French Security Incident Response Team, which rates both issues "critical."

JRE is part of Sun's Java 2 Platform Standard Edition, or J2SE. Both flaws affect J2SE 5.0 and 5.0 Update 1 for Windows, Solaris and Linux. The general JRE flaw also affects J2SE 1.4.2_07 and earlier 1.4.2 releases for those operating systems, Sun said.

The Santa Clara, Calif.-based company is urging people to install updated software to protect against possible exploitation of the security flaws. It has released two software updates to address the issues: J2SE 5.0 Update 2, which has actually been available since February, and J2SE 1.4.2_08, which was released recently, company representatives said. The software can be downloaded from the Java.com Web site.

Sun said it wasn't aware of any exploits or attacks using the flaws.

Source.

More in Tux Machines

Subsonic 5.1 Media Streamer Released, Install In Ubuntu/Linux Mint


Subsonic 5.1 Released, Install In Ubuntu/Linux Mint

Subsonic is a nice free, multi-platform web basedmedia streamer, make large collection of music handling easy. You can share music with your frineds or stream your favorite music anywhere. You can stream to multiple players simultaneously.
 
 
 
 

Read at LinuxAndUbuntu

GParted 0.21 Brings ReFS Detection, EXT4 For RHEL5, Reiser4 For Linux 3.x

Version 0.21 of the widely-used, GUI-based GNOME Partition Editor is now available. GParted 0.21 key changes according to its developers include a fix for a off by one sector error with GParted's internal block copy, support for EXT4 file-systems on RHEL/CentOS 5.x, and removing unnecessary duplicate actions when resizing a partition. Read more

Ubuntu Touch Apps Running in Unity Desktop – Video

Unity 8 for Ubuntu is coming along and Mir is also making good progress. One of the byproduct of all these improvements is that some of the apps that are designed for the Ubuntu Touch are also working on the Ubuntu desktop, with very little help. Read more