Language Selection

English French German Italian Portuguese Spanish

Java flaws open door to hackers

Filed under
Security

The flaws are "highly critical," security monitoring company Secunia said in an advisory posted Tuesday. Flaws that get that ranking--one notch below Secunia's most severe "extremely critical" rating--are typically remotely exploitable and can lead to full system compromise.

Both flaws affect the Java Runtime Environment, or JRE. This is the Java software many computer users have on their system to run Java applications. The bugs could allow a Java application to read and write files or execute applications on a victim's computer, Sun said in two separate security advisories released Monday.

One is a general flaw in the JRE, while the other is specific to Java Web Start, a technology to load Java applications over a network such as the Internet.

The flaws could be exploited through a malicious Web site, according to alerts from the French Security Incident Response Team, which rates both issues "critical."

JRE is part of Sun's Java 2 Platform Standard Edition, or J2SE. Both flaws affect J2SE 5.0 and 5.0 Update 1 for Windows, Solaris and Linux. The general JRE flaw also affects J2SE 1.4.2_07 and earlier 1.4.2 releases for those operating systems, Sun said.

The Santa Clara, Calif.-based company is urging people to install updated software to protect against possible exploitation of the security flaws. It has released two software updates to address the issues: J2SE 5.0 Update 2, which has actually been available since February, and J2SE 1.4.2_08, which was released recently, company representatives said. The software can be downloaded from the Java.com Web site.

Sun said it wasn't aware of any exploits or attacks using the flaws.

Source.

More in Tux Machines

Leftovers: KDE

South-Tyrol finances open source eInvoicing tool

Proxy FatturaPA [1], an eInvoicing software solution co-financed by the Autonomous Province of South-Tyrol (Italy), is made public using the GPLv3 free software licence. The software is developed by Link.it, a IT company based in Pisa. Read more

Linux Mint Developers Launched a New Project Called mint-dev-tools

Not only are the Linux Mint developers working on the operating systems, they are also making sure that third-party developers have a say in their project as well. That is why they have started to work on a new project called "mint-dev-tools," which is aimed specifically at devs, as the name implies. Read more

HTC One E9 Specs News, Rumors: New 'Cheaper' Android Flagship Appears In Live Images

After the One M9 that was announced earlier this month, it looks like there are more devices from the Taiwanese manufacturer than everyone expected. First on the list is the One M9 Plus, which is already expected to make an appearance in an April 8 event in China. Read more