Breaking News

SCUF Gaming Introduces the SCUF Nemesis Pro 8K PC Controller Family CORSAIR Expands the iCUE LINK Ecosystem with Quieter, Higher-Performance AIOs and Fans Razer announces XBOX 25 Anniversary Collection Apple Unveils Next-Generation Mac Lineup and Silicon Architecture M6, M5 Pro, M5 Max, and M5 Ultra Garmin expands its flagship performance smartwatch lineup with fēnix9 and fēnix9 Pro

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed

Search form

Oracle Releases Critical Patch Update for Java SE

Oracle Releases Critical Patch Update for Java SE

Enterprise & IT Feb 2,2013 0

Oracle released the February 2013 Critical Patch Update for Java SE earlier than scheduled as an active exploitation of one of the vulnerabilities affecting the Java Runtime Environment (JRE) in desktop browsers has been widely reported. The original Critical Patch Update for Java SE was scheduled on February 19th.

In addition to a number of security fixes, the February 2013 Critical Patch Update for Java SE contains fixes for 50 security vulnerabilities. 44 of these vulnerabilities only affect client deployment of Java (e.g., Java in Internet browsers). In other words, these vulnerabilities can only be exploited on desktops through Java Web Start applications or Java applets. In addition, one vulnerability affects the installation process of client deployment of Java (i.e. installation of the Java Runtime Environment on desktops).

3 of the vulnerabilities fixed in this Critical Patch Update apply to client and server deployment of Java; that means that these vulnerabilities can be exploited on desktops through Java Web Start and Java applets in Browser, or in servers, by supplying malicious input to APIs in the vulnerable server components. In some instances, the exploitation scenario of this kind of bugs on servers is very improbable; for example, one of these vulnerabilities can only be exploited against a server in the unlikely scenario that the server was allowed to process image files from an untrusted source.

Finally, 2 of the vulnerabilities fixed in this Critical Patch Update only apply to server deployment of the Java Secure Socket Extension (JSSE).

Furthermore, to help mitigate the threat of malicious applets (Java exploits in internet browsers), Oracle has switched the Java security settings to "high" by default. The "high" security setting requires users to expressly authorize the execution of unsigned applets allowing a browser user to deny execution of a suspicious applet (where in the past a suspicious applet could execute "silently"). As a result, unsuspecting users visiting malicious web sites will be notified before an applet is run and will gain the ability to deny the execution of the potentially malicious applet. In addition, Oracle has recently introduced the ability for users to disable Java in their browsers through the Java Control Panel on Windows.

For more information read the advisory for the February 2013 Critical Patch Update is located at http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html

Tags: oracle
Previous Post
X-Phone Job Online Post Feed Rumor Mill
Next Post
Twitter Says Hackers Accessed Data Of 250K Users

Related Posts

  • Cloud Service Demand Boost Oracle's Results

  • Oracle Expands Its Datacenter Infrastructure in Five New Regions Worldwide

  • Research Firm Sees a Possible Amazon-Oracle Merger

  • Oracle Expands Database Offerings

  • Microsoft and Oracle to Interconnect Microsoft Azure and Oracle Cloud

  • Oracle Accuses Google of Snooping Users

  • Mozilla Asks Supreme Court to Support Google in Case Against Oracle

  • Google asks U.S. Supreme Court to end Oracle copyright case

Latest News

SCUF Gaming Introduces the SCUF Nemesis Pro 8K PC Controller Family
Gaming

SCUF Gaming Introduces the SCUF Nemesis Pro 8K PC Controller Family

CORSAIR Expands the iCUE LINK Ecosystem with Quieter, Higher-Performance AIOs and Fans
Cooling Systems

CORSAIR Expands the iCUE LINK Ecosystem with Quieter, Higher-Performance AIOs and Fans

Razer announces XBOX 25 Anniversary Collection
Gaming

Razer announces XBOX 25 Anniversary Collection

Apple Unveils Next-Generation Mac Lineup and Silicon Architecture M6, M5 Pro, M5 Max, and M5 Ultra
Enterprise & IT

Apple Unveils Next-Generation Mac Lineup and Silicon Architecture M6, M5 Pro, M5 Max, and M5 Ultra

Garmin expands its flagship performance smartwatch lineup with fēnix9 and fēnix9 Pro
Consumer Electronics

Garmin expands its flagship performance smartwatch lineup with fēnix9 and fēnix9 Pro

Popular Reviews

Endorfy Thock V2 Wireless Keyboard

Endorfy Thock V2 Wireless Keyboard

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

The Quiet Technology Behind the Spin

The Quiet Technology Behind the Spin

SoundPeats Cove Pro

SoundPeats Cove Pro

Akaso Brave 8 Lite

Akaso Brave 8 Lite

Kioxia Exceria Plus G3 512GB microSD

Kioxia Exceria Plus G3 512GB microSD

be quiet! Dark Perk Mice

be quiet! Dark Perk Mice

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed