<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; jre update</title> <atom:link href="http://www.ghacks.net/tag/jre-update/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Fri, 10 Feb 2012 20:51:26 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Java JRE 6 Update 19 Security Update</title><link>http://www.ghacks.net/2010/03/31/java-jre-6-update-19-security-update/</link> <comments>http://www.ghacks.net/2010/03/31/java-jre-6-update-19-security-update/#comments</comments> <pubDate>Wed, 31 Mar 2010 10:59:48 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Linux]]></category> <category><![CDATA[Mac]]></category> <category><![CDATA[Operating Systems]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[java]]></category> <category><![CDATA[java runtime environment]]></category> <category><![CDATA[java update]]></category> <category><![CDATA[jre]]></category> <category><![CDATA[jre update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=24074</guid> <description><![CDATA[Today seems to be the day of the security patch. The Java Runtime Environment has received an update to JRE 6 Update 19 which fixes several security vulnerabilities. Users who have Java installed on their computer systems are encouraged to update to the latest version immediately to fix the security issues. The changelog lists all [...]]]></description> <content:encoded><![CDATA[<p>Today seems to be the day of the security patch. The Java Runtime Environment has received an update to JRE 6 Update 19 which fixes several security vulnerabilities. Users who have Java installed on their computer systems are encouraged to update to the latest version immediately to fix the security issues.</p><p>The changelog lists all the bug fixes of the latest version including changes to root certificates, an interim fix for the Transport Layer Security (TLS) Man-in-the-Middle Attack and the raising of a warning dialog if a signed application contains signed and unsigned components.</p><p>All the changes and fixes including links to further information can be accessed at the <a
href="http://www.oracle.com/technetwork/java/javase/index-140291.html">changelog</a> page.</p><p><span
id="more-24074"></span>Users can visit the JRE download page to <a
href="http://www.java.com/en/download/manual.jsp">test</a> their version of the Java Runtime Environment to evaluate if an update is necessary.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2010/03/verify_java-500x310.jpg" alt="" title="verify java" width="500" height="310" class="alignnone size-medium wp-image-24075" /></p><p>Users with outdated versions of the JRE can download it immediately from the download page for their operating system. The Java Runtime Environment is <a
href="http://www.java.com/en/download/manual.jsp">offered</a> as an offline and online installer for Windows on the standard download page.</p><p>It is recommended to check the verify Java page again after the update to make sure it was applied successfully.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/03/31/java-jre-6-update-19-security-update/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Java Security Update Released</title><link>http://www.ghacks.net/2008/12/07/java-security-update-released/</link> <comments>http://www.ghacks.net/2008/12/07/java-security-update-released/#comments</comments> <pubDate>Sun, 07 Dec 2008 17:33:08 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[java]]></category> <category><![CDATA[java ra]]></category> <category><![CDATA[java security]]></category> <category><![CDATA[java update]]></category> <category><![CDATA[java vulnerability]]></category> <category><![CDATA[jre update]]></category> <category><![CDATA[security vulnerabilities]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=8794</guid> <description><![CDATA[Sun Microsystems have issued a Java update on several critical Java security vulnerabilities. The security vulnerabilities affect several JDK, JRE and SDK versions including JRE 6 Update 10 and earlier which is usually installed to enable Java support on a computer system. A total of 13 security vulnerabilities are fixed by the Java update. Attackers [...]]]></description> <content:encoded><![CDATA[<p>Sun Microsystems have issued a Java update on several critical Java security vulnerabilities. The security vulnerabilities affect several JDK, JRE and SDK versions including JRE 6 Update 10 and earlier which is usually installed to enable Java support on a computer system.</p><p>A total of 13 security vulnerabilities are fixed by the Java update. Attackers can use those vulnerabilities for various attacks on a computer system that can lead to privilege escalations.</p><p>Probably the easiest way to uninstall old versions of Java and to install the latest secure update is by using the third party software <a
href="http://raproducts.org/">Java RA</a>. Java RA can uninstall old versions of Java. Users should download the latest <a
href="https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_US/-/USD/ViewProductDetail-Start?ProductRef=jre-6u11-oth-JPR@CDS-CDS_Developer">JRE</a> directly from Sun and install it on their systems. Java Ra should be run after the installation as it will remove all old versions of Java while keeping the latest version installed.</p><p><span
id="more-8794"></span><strong>List of vulnerabilities:</strong></p><ul><li>The Java Runtime Environment Creates Temporary Files That Have “Guessable” File Names</li><li>Java Runtime Environment (JRE) Buffer Overflow Vulnerabilities in Processing Image Files and Fonts</li><p>May<li>Allow Applets or Java Web Start Applications to Elevate Their Privileges</li><li>Multiple Security Vulnerabilities in Java Web Start and Java Plug-in May Allow Privilege Escalation</li><li>The Java Runtime Environment (JRE) “Java Update” Mechanism Does Not Check the Digital Signature of the JRE that it Downloads</li><li>A Buffer Overflow Vulnerability in the Java Runtime Environment (JRE) May Allow Privileges to be Escalated</li><li>A Security Vulnerability in the Java Runtime Environment (JRE) Related to Deserializing Calendar Objects May Allow Privileges to be Escalated</li><li>The Java Runtime Environment UTF-8 Decoder May Allow Multiple Representations of UTF-8 Input</li><li>Security Vulnerability in Java Runtime Environment May Allow Applets to List the Contents of the Current User’s Home Directory</li><li>Security Vulnerability in the Java Runtime Environment With Processing RSA Public Keys</li><li>A Security Vulnerability in Java Runtime Environment (JRE) With Authenticating Users Through Kerberos May Lead to a Denial of Service (DoS)</li><li>Security Vulnerabilities in the Java Runtime Environment (JRE) JAX-WS and JAXB Packages may Allow Privileges to be Escalated</li><li>A Security Vulnerability in Java Runtime Environment (JRE) With Parsing of Zip Files May Allow Reading of Arbitrary Memory Locations</li><li>A Security Vulnerability in the Java Runtime Environment may Allow Code Loaded From the Local Filesystem to Access LocalHost</li></ul><p>Users who cannot install the Java update immediately should disable Java for the time being to protect their computer system from the exploits.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/12/07/java-security-update-released/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> </channel> </rss>
