Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Click for more information, or
Home Enterprise I.T. Cloud Computing Applications Hardware More Topics...
Apple/Mac
24/7/365 Network Uptime!
Average Rating:
Rate this article:  
Oracle Rushes Out New Java Zero-Day Patches
Oracle Rushes Out New Java Zero-Day Patches

By Jennifer LeClaire
March 5, 2013 2:08PM

    Bookmark and Share
"The smart and safe approach to using Java is to use a two-browser approach so that you have one browser without Java for your daily Web surfing and use a different browser strictly for the use of Java," said security researcher Jerome Segura. "An even safer approach for enterprises is to use dedicated virtual machines for Web browsing with Java."
 



Oracle just rolled out a new Database Appliance, complete with virtualization, but news of more Java security woes may be overshadowing the announcement. Oracle has released a new Java update to patch zero-day vulnerabilities.

According to Oracle, the Security Alert addresses security issues CVE-2013-1493 and another vulnerability affecting Java running in web browsers. Oracle was quick to point out that the vulnerabilities do not apply to Java running on servers, standalone Java desktop applications or embedded Java applications. They also do not affect Oracle server-based software.

"These vulnerabilities may be remotely exploitable without authentication, i.e., they may be exploited over a network without the need for a username and password," Oracle said in its security alert. "For an exploit to be successful, an unsuspecting user running an affected release in a browser must visit a malicious web page that leverages these vulnerabilities. Successful exploits can impact the availability, integrity, and confidentiality of the user's system."

Skirting Java

"Recent attacks against Apple, Facebook and Twitter all used Java zero-days to penetrate the companies' networks and install Remote Administration Trojans," Malwarebytes researcher Jerome Segura told us. "What is important to realize is that no matter how up-to-date those systems were, even with anti-virus and firewall, they still got compromised. This shows just how dangerous Web exploits and zero-days are."

The most common advice is to remove or disable Java however, noted Segura, however many applications depend on Java and removing it would be a problem.

"The smart and safe approach to using Java is to use a two-browser approach so that you have one browser without Java for your daily Web surfing and use a different browser strictly for the use of Java," he said. "An even safer approach for enterprises is to use dedicated virtual machines for Web browsing with Java, and other plug-ins, for that matter."

Oracle Feeling Java Heat

Oracle has been working hard to keep Java patched in 2013. Oracle patched at least 55 flaws in Java in February. In January, Oracle offered a Java 7 update that fixed zero-day flaws that were being actively exploited in the wild.

"The company intended to include a fix for CVE-2013-1493 in the April 16, 2013, Critical Patch Update for Java SE (note that Oracle recently announced its intent to have an additional Java SE security release on this date in addition to those previously scheduled in June and October of 2013)," Eric Maurice, Oracle's director of Software Assurance, wrote in a blog post. "However, in light of the reports of active exploitation of CVE-2013-1493, and in order to help maintain the security posture of all Java SE users, Oracle decided to release a fix for this vulnerability and another closely related bug as soon as possible through this Security Alert."

Oracle and Maurice are feeling the heat. He said Oracle is committed to accelerating the release of security fixes for Java SE, particularly to help address the security-worthiness of Java running in browsers. The quick release of this Security Alert, the higher number of Java SE fixes included in recent Critical Patch Updates, he said, and the announcement of an additional security release date for Java SE -- the April 16 Critical Patch Update for Java SE -- are examples of that commitment.
 

Tell Us What You Think
Comment:

Name:





 Apple/Mac
1.   Will Next OS X Bring New Apple Grief?
2.   Apple and Samsung Feel the Heat
3.   Apple Faces Suit Over Work Breaks
4.   Earnings, Excitement Grow for Apple
5.   Mac OS Yosemite Beta 4 Released


advertisement
Apple Digital Book Settlement Set
But company still appealing decision.
Average Rating:
Earnings, Excitement Grow for Apple
Momentum mounts as rumors swirl.
Average Rating:
Mac OS Yosemite Beta 4 Released
Public preview could be coming soon.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
Researchers Working To Fix Tor Security Exploit
Developers for the Tor privacy browser are scrambling to fix a bug revealed Monday that researchers say could allow hackers, or government surveillance agencies, to track users online.
 
Wall Street Journal Hacked Again
Hacked again. That’s the story at the Wall Street Journal this week as the newspaper reports that the computer systems housing some of its news graphics were breached. Customers not affected -- yet.
 
Dropbox for Business Beefs Up Security
Dropbox is upping its game for business users. The cloud-based storage and sharing company has rolled out new security, search and other features to boost its appeal for businesses.
 

Enterprise Hardware Spotlight
Watson Gets His First Customer Service Gig
Since appearing on Jeopardy, IBM's Watson supercomputer has been making a living using his super-intelligent knowledge base for business verticals. Now, Watson's been hired for his first customer service job.
 
Tablet Giants Apple and Samsung Feel the Heat
When a company saturates its home market with a once-hot product, expect it to pump up efforts elsewhere. Apple, for its part, is now pushing iPads to big corporations and the enterprise market.
 
Microsoft Makes Design Central to Its Future
Over the last four years, Microsoft has doubled the number of designers it employs, putting a priority on fashioning devices that work around people's lives -- and that are attractive and cool.
 

Mobile Technology Spotlight
T-Mobile Calls 'BS' on AT&T's New Promotion
While Verizon Wireless is moving to throttle bandwidth hogs, a scrappy T-Mobile is taking on the giants with a limited-time promotion it hopes will drive up the churn rates of its wireless rivals.
 
Microsoft Update to Windows Phone 8.1 Already Coming
An update to Windows Phone 8.1 is on the way just weeks after the release of the product itself. Microsoft has begun detailing some of the update features to phone manufacturers.
 
Stanford Researchers Report Battery Breakthrough
Stanford researchers have found a way to use lithium in a battery's anode, a breakthrough that could triple capacity and has been described as the "holy grail of battery science."
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud Computing | Applications | Hardware | Mobile Tech | Big Data | Communications
World Wide Web | Network Security | Data Storage | CRM Systems | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.