<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; java update</title>
	<atom:link href="http://www.ghacks.net/tag/java-update/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 03:24:03 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Java Security Update Released</title>
		<link>http://www.ghacks.net/2008/12/07/java-security-update-released/</link>
		<comments>http://www.ghacks.net/2008/12/07/java-security-update-released/#comments</comments>
		<pubDate>Sun, 07 Dec 2008 17:33:08 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[java ra]]></category>
		<category><![CDATA[java security]]></category>
		<category><![CDATA[java update]]></category>
		<category><![CDATA[java vulnerability]]></category>
		<category><![CDATA[jre update]]></category>
		<category><![CDATA[security vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=8794</guid>
		<description><![CDATA[Sun Microsystems have issued a Java update on several critical Java security vulnerabilities. The security vulnerabilities affect several JDK, JRE and SDK versions including JRE 6 Update 10 and earlier which is usually installed to enable Java support on a computer system.
A total of 13 security vulnerabilities are fixed by the Java update. Attackers can [...]]]></description>
			<content:encoded><![CDATA[<p>Sun Microsystems have issued a Java update on several critical Java security vulnerabilities. The security vulnerabilities affect several JDK, JRE and SDK versions including JRE 6 Update 10 and earlier which is usually installed to enable Java support on a computer system.</p>
<p>A total of 13 security vulnerabilities are fixed by the Java update. Attackers can use those vulnerabilities for various attacks on a computer system that can lead to privilege escalations.</p>
<p>Probably the easiest way to uninstall old versions of Java and to install the latest secure update is by using the third party software <a href="http://raproducts.org/">Java RA</a>. Java RA can uninstall old versions of Java. Users should download the latest <a href="https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_US/-/USD/ViewProductDetail-Start?ProductRef=jre-6u11-oth-JPR@CDS-CDS_Developer">JRE</a> directly from Sun and install it on their systems. Java Ra should be run after the installation as it will remove all old versions of Java while keeping the latest version installed.</p>
<p><span id="more-8794"></span><strong>List of vulnerabilities:</strong></p>
<ul>
<li>The Java Runtime Environment Creates Temporary Files That Have “Guessable” File Names </li>
<li>Java Runtime Environment (JRE) Buffer Overflow Vulnerabilities in Processing Image Files and Fonts </li>
<p>May
<li>Allow Applets or Java Web Start Applications to Elevate Their Privileges </li>
<li>Multiple Security Vulnerabilities in Java Web Start and Java Plug-in May Allow Privilege Escalation </li>
<li>The Java Runtime Environment (JRE) “Java Update” Mechanism Does Not Check the Digital Signature of the JRE that it Downloads </li>
<li>A Buffer Overflow Vulnerability in the Java Runtime Environment (JRE) May Allow Privileges to be Escalated </li>
<li>A Security Vulnerability in the Java Runtime Environment (JRE) Related to Deserializing Calendar Objects May Allow Privileges to be Escalated </li>
<li>The Java Runtime Environment UTF-8 Decoder May Allow Multiple Representations of UTF-8 Input </li>
<li>Security Vulnerability in Java Runtime Environment May Allow Applets to List the Contents of the Current User’s Home Directory </li>
<li>Security Vulnerability in the Java Runtime Environment With Processing RSA Public Keys </li>
<li>A Security Vulnerability in Java Runtime Environment (JRE) With Authenticating Users Through Kerberos May Lead to a Denial of Service (DoS) </li>
<li>Security Vulnerabilities in the Java Runtime Environment (JRE) JAX-WS and JAXB Packages may Allow Privileges to be Escalated </li>
<li>A Security Vulnerability in Java Runtime Environment (JRE) With Parsing of Zip Files May Allow Reading of Arbitrary Memory Locations </li>
<li>A Security Vulnerability in the Java Runtime Environment may Allow Code Loaded From the Local Filesystem to Access LocalHost </li>
</ul>
<p>Users who cannot install the Java update immediately should disable Java for the time being to protect their computer system from the exploits.</p>

	Tags: <a href="http://www.ghacks.net/tag/java/" title="java" rel="tag">java</a>, <a href="http://www.ghacks.net/tag/java-ra/" title="java ra" rel="tag">java ra</a>, <a href="http://www.ghacks.net/tag/java-security/" title="java security" rel="tag">java security</a>, <a href="http://www.ghacks.net/tag/java-update/" title="java update" rel="tag">java update</a>, <a href="http://www.ghacks.net/tag/java-vulnerability/" title="java vulnerability" rel="tag">java vulnerability</a>, <a href="http://www.ghacks.net/tag/jre-update/" title="jre update" rel="tag">jre update</a>, <a href="http://www.ghacks.net/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/04/09/update-java-and-remove-old-java-versions-from-your-system/" title="Update Java and remove old Java versions from your system (April 9, 2008)">Update Java and remove old Java versions from your system</a> (10)</li>
	<li><a href="http://www.ghacks.net/2008/04/18/windows-vulnerability-scanner/" title="Windows Vulnerability Scanner (April 18, 2008)">Windows Vulnerability Scanner</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/10/29/turn-your-mobile-phone-into-a-pc-remote-control/" title="Turn Your Mobile Phone Into A PC Remote Control (October 29, 2008)">Turn Your Mobile Phone Into A PC Remote Control</a> (22)</li>
	<li><a href="http://www.ghacks.net/2007/08/02/secure-wordpress-with-the-first-wordpress-worm/" title="Secure Wordpress with the first Wordpress Worm (August 2, 2007)">Secure Wordpress with the first Wordpress Worm</a> (7)</li>
	<li><a href="http://www.ghacks.net/2009/02/05/photo-collage/" title="Photo Collage (February 5, 2009)">Photo Collage</a> (3)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/12/07/java-security-update-released/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Update Java and remove old Java versions from your system</title>
		<link>http://www.ghacks.net/2008/04/09/update-java-and-remove-old-java-versions-from-your-system/</link>
		<comments>http://www.ghacks.net/2008/04/09/update-java-and-remove-old-java-versions-from-your-system/#comments</comments>
		<pubDate>Wed, 09 Apr 2008 08:09:58 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[java runtime environment]]></category>
		<category><![CDATA[java update]]></category>
		<category><![CDATA[jre]]></category>
		<category><![CDATA[sun]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=3760</guid>
		<description><![CDATA[JavaRa is a small application for Microsoft Windows that serves two purposes. The first is to check if a Java update is available and if that is the case download and install it on the computer. The second scans the system for previous versions of Java, if any old versions are found on the system [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://prm753.bchea.org/software.html">JavaRa</a> is a small application for Microsoft Windows that serves two purposes. The first is to check if a Java update is available and if that is the case download and install it on the computer. The second scans the system for previous versions of Java, if any old versions are found on the system they are removed from it. This second option is very handy because Java, more precisely its Java Runtime Environment, tends to install itself in separate directories with each new version that is released.</p>
<p>Four different versions of the Java Runtime Environment were installed on my system and JavaRa removed the three versions of JRE that were the oldest from the system. I started by scanning my system for old versions of Java which were removed, then checked if there was a Java update available. I should have done it the other way round because an update was found and a new version of Java was installed on my system.</p>
<p>Which led to the fact that the previously newest version was not the newest anymore so I had to run the cleanup process again to remove that version. The best way to use the application is therefor to run the Update first and check for old versions once the software has checked for and installed possible updates.</p>
<p><span id="more-3760"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/java/" title="java" rel="tag">java</a>, <a href="http://www.ghacks.net/tag/java-runtime-environment/" title="java runtime environment" rel="tag">java runtime environment</a>, <a href="http://www.ghacks.net/tag/java-update/" title="java update" rel="tag">java update</a>, <a href="http://www.ghacks.net/tag/jre/" title="jre" rel="tag">jre</a>, <a href="http://www.ghacks.net/tag/sun/" title="sun" rel="tag">sun</a>, <a href="http://www.ghacks.net/tag/windows/" title="Windows" rel="tag">Windows</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/02/08/jdarkroom-productively-word-process/" title="jDarkRoom: Productively word process (February 8, 2009)">jDarkRoom: Productively word process</a> (5)</li>
	<li><a href="http://www.ghacks.net/2008/12/07/java-security-update-released/" title="Java Security Update Released (December 7, 2008)">Java Security Update Released</a> (4)</li>
	<li><a href="http://www.ghacks.net/2007/01/15/bang-howdy-free-strategic-multiplayer-game/" title="Bang Howdy Free Strategic Multiplayer Game (January 15, 2007)">Bang Howdy Free Strategic Multiplayer Game</a> (1)</li>
	<li><a href="http://www.ghacks.net/2006/10/21/zoom-it/" title="Zoom It (October 21, 2006)">Zoom It</a> (4)</li>
	<li><a href="http://www.ghacks.net/2008/06/08/zip-repair/" title="Zip Repair (June 8, 2008)">Zip Repair</a> (3)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/04/09/update-java-and-remove-old-java-versions-from-your-system/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>
