Yes, Java Again

Corrine

Administrator,
Microsoft MVP,
Security Analyst
Staff member
Joined
Feb 22, 2012
Posts
12,394
Location
Upstate, NY
It ain't over until Oracle stops with the bandaids and cleans up Java:

A security research team that has alerted Oracle to a series of security flaws in Java in the past, says that it has uncovered new zero-day vulnerabilities in the software.

According to Polish firm update posted by Security Explorations, it has sent proof-of-concept code to Oracle's security team - so they can investigate the issue.

The concern is that the flaws could be exploited to completely bypass Java's security sandbox and infect computers in a similar fashion to the attacks which recently troubled the likes of Facebook, Apple and Microsoft.

In those cases, cybercriminals hacked legitimate websites and planted code which exploited Java vulnerabilities when developers visited using web browsers that had a vulnerable version of the Java plugin.

Full story at Researchers claim to have found more zero-day vulnerabilities in Java | Naked Security

Also see Java’s latest security problems: New flaw identified, old one attacked | Ars Technica

~~~~~~~~~~~~~

Do you really need Java? See Java, The Never-Ending Saga ~ Security Garden.
 
Thanks Corrine!

Oracle really needs to clean up their act! They have done some badly needed fixes, but so much more is needed!


I have totally removed Java from my every day browser and every browser but one on my system. And that one I enable and disable as needed.

They have made it so hard for those of us who actually need Java. Really upsetting!
 

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top