Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Please click for more information, or scroll down to pass the ad, or Close Ad.
Home Enterprise I.T. Cloud Computing Applications Hardware More Topics...
Applications
24/7/365 Network Uptime
Average Rating:
Rate this article:  
Oracle Rushes Out New Java Zero-Day Patches
Oracle Rushes Out New Java Zero-Day Patches

By Jennifer LeClaire
March 5, 2013 2:08PM

    Bookmark and Share
"The smart and safe approach to using Java is to use a two-browser approach so that you have one browser without Java for your daily Web surfing and use a different browser strictly for the use of Java," said security researcher Jerome Segura. "An even safer approach for enterprises is to use dedicated virtual machines for Web browsing with Java."
 



Oracle just rolled out a new Database Appliance, complete with virtualization, but news of more Java security woes may be overshadowing the announcement. Oracle has released a new Java update to patch zero-day vulnerabilities.

According to Oracle, the Security Alert addresses security issues CVE-2013-1493 and another vulnerability affecting Java running in web browsers. Oracle was quick to point out that the vulnerabilities do not apply to Java running on servers, standalone Java desktop applications or embedded Java applications. They also do not affect Oracle server-based software.

"These vulnerabilities may be remotely exploitable without authentication, i.e., they may be exploited over a network without the need for a username and password," Oracle said in its security alert. "For an exploit to be successful, an unsuspecting user running an affected release in a browser must visit a malicious web page that leverages these vulnerabilities. Successful exploits can impact the availability, integrity, and confidentiality of the user's system."

Skirting Java

"Recent attacks against Apple, Facebook and Twitter all used Java zero-days to penetrate the companies' networks and install Remote Administration Trojans," Malwarebytes researcher Jerome Segura told us. "What is important to realize is that no matter how up-to-date those systems were, even with anti-virus and firewall, they still got compromised. This shows just how dangerous Web exploits and zero-days are."

The most common advice is to remove or disable Java however, noted Segura, however many applications depend on Java and removing it would be a problem.

"The smart and safe approach to using Java is to use a two-browser approach so that you have one browser without Java for your daily Web surfing and use a different browser strictly for the use of Java," he said. "An even safer approach for enterprises is to use dedicated virtual machines for Web browsing with Java, and other plug-ins, for that matter."

Oracle Feeling Java Heat

Oracle has been working hard to keep Java patched in 2013. Oracle patched at least 55 flaws in Java in February. In January, Oracle offered a Java 7 update that fixed zero-day flaws that were being actively exploited in the wild.

"The company intended to include a fix for CVE-2013-1493 in the April 16, 2013, Critical Patch Update for Java SE (note that Oracle recently announced its intent to have an additional Java SE security release on this date in addition to those previously scheduled in June and October of 2013)," Eric Maurice, Oracle's director of Software Assurance, wrote in a blog post. "However, in light of the reports of active exploitation of CVE-2013-1493, and in order to help maintain the security posture of all Java SE users, Oracle decided to release a fix for this vulnerability and another closely related bug as soon as possible through this Security Alert."

Oracle and Maurice are feeling the heat. He said Oracle is committed to accelerating the release of security fixes for Java SE, particularly to help address the security-worthiness of Java running in browsers. The quick release of this Security Alert, the higher number of Java SE fixes included in recent Critical Patch Updates, he said, and the announcement of an additional security release date for Java SE -- the April 16 Critical Patch Update for Java SE -- are examples of that commitment.
 

Tell Us What You Think
Comment:

Name:



APC has an established a reputation for solid products that virtually pay for themselves upon installation. Who has time to spend worrying about system downtime? APC makes it easy for you to focus on business growth instead of business downtime with reliable data center systems and IT solutions. Learn more here.


 Applications
1.   Silverpop: IBM Marketing Gets Personal
2.   VMware Horizon 6 Folds In AirWatch
3.   Cuban Twitter Creates New Hurdles
4.   Wedding in the Palm of Your Hand
5.   Last Fixes Tuesday for XP, Office 2003


advertisement
Last Fixes Tuesday for XP, Office 2003
Microsoft closing out support for two.
Average Rating:
VMware Horizon 6 Folds In AirWatch
Delivers both published apps, desktops.
Average Rating:
Cuban Twitter Creates New Hurdles
More work for bloggers, dissidents.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
How To Beat the Heartbleed Bug
Heartbleed headlines continue as IT admins scramble for answers no one has. Early reports of stolen personal data, including 900 social insurance numbers in Canada, are starting to trickle in.
 
After Heartbleed, OpenSSL Calls for More Support
The president of the OpenSSL Foundation says more support is needed from companies and governments that use its software so that it can better spot and fix flawed pieces of code such as Heartbleed.
 
NSC Backs Disclosing Software Vulnerabilities
Disclosing vulnerabilities in commercial and open source software is in the national interest and shouldn't be withheld unless there is a clear need, says the National Security Council.
 

Enterprise Hardware Spotlight
Vaio Fit 11A Battery Danger Forces Recall by Sony
Using a Sony Vaio Fit 11A laptop? It's time to send it back to Sony. In fact, Sony is encouraging people to stop using the laptop after several reports of its Panasonic battery overheating.
 
Continued Drop in Global PC Shipments Slows
Worldwide shipments of PCs fell during the first three months of the year, but the global slump in PC demand may be easing, with a considerable slowdown from last year's drops.
 
Google Glass Finds a Home in Medical Education, Practice
Google Glass may find its first markets in verticals in which hands-free access to data is a boon. Medicine is among the most prominent of those, as seen in a number of Glass experiments under way.
 

Mobile Technology Spotlight
Amazon 3D Smartphone Pics Leaked
E-commerce giant Amazon is reportedly set to launch a smartphone after years of development. Photos of the phone, which may feature a unique 3D interface, were leaked by tech pub BGR.
 
Zebra Tech Buys Motorola Enterprise for $3.45B
Weeks after Lenovo bought Motorola Mobility’s assets from Google for $2.91 million, Zebra Technologies is throwing down $3.45 billion for Motorola’s Enterprise business in an all-cash deal.
 
CTIA Caves, Volunteers Kill Switch Plan
After bucking against the concept of a smartphone kill switch, the CTIA just announced the “Smartphone Anti-Theft Voluntary Commitment” to thwart smartphone thefts in the U.S.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud Computing | Applications | Hardware | Mobile Tech | Big Data | Communications
World Wide Web | Network Security | Data Storage | Small Business | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.