Oracle releases Java patch update
The February patch was offered today -- ahead of schedule -- and contains fixes for 50 vulnerabilities
Infoworld - Oracle on Friday released a critical patch update for Java SE, offering the patch ahead of schedule to stave off an active exploitation affecting the Java Runtime Environment in desktop browsers. Server-side fixes are being offered as well.
Initially scheduled for release on February 19, the February 2013 critical patch update contains fixes for 50 vulnerabilities. Java has been under fire lately for security issues, particularly affecting browsers, and Oracle recently vowed to be more communicative about what it is doing to fix these problems. "The popularity of the Java Runtime Environment in desktop browsers and the fact that Java in browsers is OS-independent makes Java an attractive target for malicious hackers," Oracle said in its bulletin on Friday.
[ InfoWorld columnist Andrew Oliver vouches for Java's runtime security. | Sign up for InfoWorld's Enterprise Java newsletter for more news on Java. ]
Forty-four of the 50 vulnerabilities impact Java in Internet browsers. "In other words, these vulnerabilities can only be exploited on desktops through Java Web Start applications or Java applets," Oracle said. "In addition, one vulnerability affects the installation process of client deployment of Java (i.e. installation of the Java Runtime Environment on desktops). Note also that this Critical Patch Update includes the fixes that were previously released through Security Alert CVE-2013-0422."
Additionally, three of the vulnerabilities apply to client and server deployments of Java, in which these can be exploited on desktops through Java Web Start or browser applets or in servers by supplying malicious input to APIs in vulnerable components. "In some instances, the exploitation scenario of this kind of bugs on servers is very improbable; for example, one of these vulnerabilities can only be exploited against a server in the unlikely scenario that the server was allowed to process image files from an untrusted source." Two vulnerabilities fixed in the update only apply to server-side deployment of the Java Secure Socket Extension, but most of the vulnerabilities addressed in the patch update affect Java and JavaFX client deployments, Oracle noted. "This reflects the fact that the Java server environment is more secure than the Java Runtime Environment in browsers because servers operate in a more secure and controlled environment."
This article, "Oracle releases Java patch update," was originally published at InfoWorld.com. Follow the latest developments in business technology news and get a digest of the key stories each day in the InfoWorld Daily newsletter. For the latest developments in business technology news, follow InfoWorld.com on Twitter.
Read more about security in InfoWorld's Security Channel.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Your Data under Siege: Defeating the Enemy of Complexity Even if you have adequate antivirus protection, are there still holes in your IT security armor? Is lack of bandwidth to manage the...
- Best Practices for Cloud-based Information Governance This paper explores the latest ideas on evaluating cloud deployment: public or private clouds, data location and privacy, data ownership and access, and...
- Social Media and the Shifting Information Compliance Landscape Packed with practical advice, the white paper includes a 'model solution for social media' that outlines four best practices to help information professionals...
- Meet your Dodd-Frank recordkeeping compliance requirements Download this white paper for IT professionals to learn about a DFA solution that enables any financial organization to harness existing IT investments...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts