Apple patches months-old Java bugs
Fixes more than two-dozen bugs Sun patched in March for Windows, Linux
September 25, 2008 12:00 PM ETComputerworld - Apple Inc. patched nearly 30 Java vulnerabilities in Mac OS X yesterday, months after Sun Microsystems Inc., Java's developer, fixed most of the same flaws for other operating systems.
The separate updates for Mac OS X 10.5 (Leopard) and Mac OS X 10.4 (Tiger) patched 27 and 23 bugs, respectively.
Two of the vulnerabilities in Leopard, only one of which was also present in Tiger, are specific to Mac OS, and attackers could use them to execute malicious code. Both of these critical bugs could be triggered by specially-crafted Java applets if the user was tricked into visiting a malicious Web site, Apple noted.
However, the bulk of the vulnerabilitie were not Mac-specific and had been patched by Sun for Windows, Linux and Solaris as far back as March 2008. Unlike its operating system rivals, Apple maintains its own version of Java and so is responsible for handling updates for machines running OS X.
Apple has been criticized for its sluggish patching of third-party components, particularly open-source code, that it bundles with Mac OS. More than a year ago, Charles Miller, a researcher at Independent Security Evaluators LLC, called Apple's inability to keep up with open-source fixes "negligent."
Yesterday's update brings Java SE 6 to Version 1.6.0_07, J2SE 5.0 to Version 1.5.0_16, and J2SE 1.4.2 to 1.4.2_18. All are the most current versions available from Sun, which last patched Java for Windows, Linux and Solaris in July.
Related Story
Apple
Additional Resources



White Papers & Webcasts
Share our Strength
Download Now
Extending Client Refresh - 11 Steps to Maximize Savings
Register Now!
Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Eradicate Spam & Gain 100% Asurance of Clean Mailboxes
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Consolidate Your Servers and Storage to Lower Costs with Oracle Database 11g
Register for this webcast!
Not Just Words: Enforce Your Email and Web Acceptable Usage Policies
Get this paper now!
The Commercialization of ITIL: Lessons Learned
Register for this event today!
