There are a number of really good reasons to update to the latest version
of Java. Not the least of which is the fact that older versions of the Java
Runtime Environment have now been reported to be at risk from seven highly
critical vulnerabilities.
scv.bu.edu/Doc/Java/Text/java.cert.txt:: with malicious intent, and users are at risk only when connecting to untrusted web pages. A. Java Development Kit users Sun reports that source-level http://scv.bu.edu/Doc/Java/Text/java.cert.txtHOME |
Sun advisory number 102171 describes the vulnerabilities and is titled,
"Security Vulnerabilities in the Java Runtime Environment may Allow an
Untrusted Applet to Elevate its Privileges."
According to security firm Secunia, various unspecified errors in the "reflection" APIs cause the vulnerabilities, which could lead to a system compromise.
Slashdot | Microsoft Flubs Patch, Putting Users At Risk:: Microsoft Flubs Patch, Putting Users At Risk -- article related to Security, Windows, and Internet Explorer. with lots of stuff going on (Java and Flash) http://it.slashdot.org/it/06/08/22/194245.shtmlHOME | Risk Analysis - Overview - Frontline Systems:: simulation optimization in Excel, Visual Basic, VB.NET, C#, C++, Java and MATLAB Users. for Developers. Premium Solver. Premium Solver Platform. Risk http://www.solver.com/risk-analysisHOME |
Sun's advisory does not specify what the actual errors are. A Sun
spokesperson was not immediately available for comment.
The first advisories related to the vulnerabilities in the "reflection"
APIs date back to at least November when the company issued Sun Alert ID: 102003, which identified three vulnerabilities.
Bug bites Macintosh Java - CNET News.com:: Mac users who are browsing the Web with Apples latest Java technology could be exposing their local files to risk. A CNET article by Alex Lash, Staff Writer, CNET http://news.cnet.com/2100-1001-204824.html?legacy=cnet&feed.cnetbriefsHOME | IBM issued its own "technote faq" in December.
Java Runtime Edition (JRE) 5.0 and Java Development Kit (JDK) update 5 and
earlier are reported to be at risk from the vulnerabilities. The most
current version of JRE 5.0 is update 6, which has already fixed the seven newly
disclosed vulnerabilities.
Java users of all OS flavors, including Windows, Linux and Solaris, are
strongly encouraged to upgrade their JREs.
ICS to Buy, Open Source, Project.net
BitTorrent Finds Way Into Opera
|