Researchers claim Java still has 'vulnerabilities'

Oracle
Oracle's swift response may be inadequate

Security Explorations researcher Adam Gowdiak posted a message on Friday stating that his team had discovered not one, not two, but three security holes in Java's latest version.

According to Gowdiak, one of the security risks manifests as the same problem for which Oracle recently released emergency patch Java 7 Update 11.

The vulnerability allows clever hackers to gain a "complete Java security sandbox bypass", a persisting problem that prompted the U.S. Department of Homeland Security to recommend disabling the software temporarily.

Security Explorations also found two new security flaws in "recent version of Java SE7 code," which it has submitted to Oracle for review, and hopefully for a fix.

Java jams

The researchers at Security Explorations cited the exploiter group Immunity as one of their sources in discovering the still-vulnerable portion of Java code after the patch was issued.

A quick browse through Immunity's findings shows that the remaining flaw is predicated on the signing of a Java applet, and that the flaw is not present in Java 6, which has been confirmed by Oracle.

Because of the prompt added by the Java 7 Update 11, a portion of the initial security hole has been filled, and unsigned applets can no longer gain access by that method.

However, if the new holes discovered by Gowdiak and team are legitimate threats, it may be advisable to keep Java disabled for browsers until Oracle responds with another, more complete fix.

Via PCWorld

Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)