Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Programming > Java > JDK 1.7.0_11 is out.

Reply
Thread Tools

JDK 1.7.0_11 is out.

 
 
Roedy Green
Guest
Posts: n/a
 
      01-14-2013
Presumably will fix the 0-day exploit.
I will find out after I get it myself.
--
Roedy Green Canadian Mind Products http://mindprod.com
Students who hire or con others to do their homework are as foolish
as couch potatoes who hire others to go to the gym for them.
 
Reply With Quote
 
 
 
 
Arne Vajhøj
Guest
Posts: n/a
 
      01-14-2013
On 1/13/2013 9:24 PM, Roedy Green wrote:
> Presumably will fix the 0-day exploit.


It does.

Arne


 
Reply With Quote
 
 
 
 
Roedy Green
Guest
Posts: n/a
 
      01-15-2013
On Sun, 13 Jan 2013 18:24:23 -0800, Roedy Green
<> wrote, quoted or indirectly quoted
someone who said :

>Presumably will fix the 0-day exploit.
>I will find out after I get it myself.


the release notes are at
http://www.oracle.com/technetwork/ja...s-1896856.html

As I read them the "fix" is just to turn off Applets entirely, by
default -- hardly a fix. Perhaps one of the group's language lawyers
could see if I interpreted that correctly.
--
Roedy Green Canadian Mind Products http://mindprod.com
The first 90% of the code accounts for the first 90% of the development time.
The remaining 10% of the code accounts for the other 90% of the development
time.
~ Tom Cargill Ninety-ninety Law
 
Reply With Quote
 
Arne Vajhøj
Guest
Posts: n/a
 
      01-16-2013
On 1/14/2013 11:01 PM, Roedy Green wrote:
> On Sun, 13 Jan 2013 18:24:23 -0800, Roedy Green
> <> wrote, quoted or indirectly quoted
> someone who said :
>
>> Presumably will fix the 0-day exploit.
>> I will find out after I get it myself.

>
> the release notes are at
> http://www.oracle.com/technetwork/ja...s-1896856.html
>
> As I read them the "fix" is just to turn off Applets entirely, by
> default -- hardly a fix. Perhaps one of the group's language lawyers
> could see if I interpreted that correctly.


I don't read it that way.

<quote>
This release contains fixes for security vulnerabilities. For more
information, see Oracle Security Alert for CVE-2013-0422.

In addition, the following change has been made:

Area: deploy
Synopsis: Default Security Level Setting Changed to High
The default security level for Java applets and web start applications
has been increased from "Medium" to "High".
</quote>

.... contains fixes ... in addition ... security level
setting changed ...

I can not interpret that other than there are both a fix
and a change in default security level.

Arne


 
Reply With Quote
 
Eric Sosman
Guest
Posts: n/a
 
      01-16-2013
On 1/15/2013 9:03 PM, Arne Vajhøj wrote:
>[...]
> <quote>
> This release contains fixes for security vulnerabilities. For more
> information, see Oracle Security Alert for CVE-2013-0422.


CERT's advice is

"Immunity has indicated that only the reflection
vulnerability has been fixed and that the JMX MBean
vulnerability remains. [...] Unless it is absolutely
necessary to run Java in web browsers, disable it as
described below, even after updating to 7u11. [...]"
--from <http://www.kb.cert.org/vuls/id/625617>

Write once, pwn anywhere ...

--
Eric Sosman
d
 
Reply With Quote
 
Arne Vajhøj
Guest
Posts: n/a
 
      01-17-2013
On 1/15/2013 10:03 PM, Eric Sosman wrote:
> On 1/15/2013 9:03 PM, Arne Vajhøj wrote:
>> [...]
>> <quote>
>> This release contains fixes for security vulnerabilities. For more
>> information, see Oracle Security Alert for CVE-2013-0422.

>
> CERT's advice is
>
> "Immunity has indicated that only the reflection
> vulnerability has been fixed and that the JMX MBean
> vulnerability remains. [...] Unless it is absolutely
> necessary to run Java in web browsers, disable it as
> described below, even after updating to 7u11. [...]"
> --from <http://www.kb.cert.org/vuls/id/625617>
>
> Write once, pwn anywhere ...


According to the link then the exploits require both
vulnerabilities.

But obviously the unfixed problem could be part of new
exploits as well.

So it definitely should be fixed. And hopefully it
will be.

Arne


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
JDK 1.5 or JDK 1.6 Pep Java 19 07-15-2007 12:06 AM
regarding JDk 141 and JDK 122 for linux 64 bit Platform Jaggu Java 3 01-08-2007 10:47 AM
What is the difference between J2EE, JDK, JDK-SDK, JRE and J2SE packages ? Ulf Meinhardt Java 0 08-10-2006 07:12 PM
jEdit: compiles JDK 1.5.0 ok, but runs JDK 1.4.1 (why?) Thomas G. Marshall Java 5 08-06-2004 04:12 AM
Help with converting IDS from JDK 1.1 to JDK 1.4 Babar Java 1 05-20-2004 09:11 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57