<?xml version="1.0" encoding="UTF-8"?> <rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" ><channel><title>gHacks technology news &#187; jre update</title> <atom:link href="http://www.ghacks.net/tag/jre-update/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Fri, 19 Mar 2010 17:29:08 +0000</lastBuildDate> <generator>http://wordpress.org/?v=2.9.2</generator> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <item><title>Java Security Update Released</title><link>http://www.ghacks.net/2008/12/07/java-security-update-released/</link> <comments>http://www.ghacks.net/2008/12/07/java-security-update-released/#comments</comments> <pubDate>Sun, 07 Dec 2008 17:33:08 +0000</pubDate> <dc:creator>Martin</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[java]]></category> <category><![CDATA[java ra]]></category> <category><![CDATA[java security]]></category> <category><![CDATA[java update]]></category> <category><![CDATA[java vulnerability]]></category> <category><![CDATA[jre update]]></category> <category><![CDATA[security vulnerabilities]]></category><guid isPermaLink="false">http://www.ghacks.net/?p=8794</guid> <description><![CDATA[Sun Microsystems have issued a Java update on several critical Java security vulnerabilities. The security vulnerabilities affect several JDK, JRE and SDK versions including JRE 6 Update 10 and earlier which is usually installed to enable Java support on a computer system. A total of 13 security vulnerabilities are fixed by the Java update. Attackers can [...]]]></description> <content:encoded><![CDATA[<p>Sun Microsystems have issued a Java update on several critical Java security vulnerabilities. The security vulnerabilities affect several JDK, JRE and SDK versions including JRE 6 Update 10 and earlier which is usually installed to enable Java support on a computer system.</p><p>A total of 13 security vulnerabilities are fixed by the Java update. Attackers can use those vulnerabilities for various attacks on a computer system that can lead to privilege escalations.</p><p>Probably the easiest way to uninstall old versions of Java and to install the latest secure update is by using the third party software <a href="http://raproducts.org/">Java RA</a>. Java RA can uninstall old versions of Java. Users should download the latest <a href="https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_Developer-Site/en_US/-/USD/ViewProductDetail-Start?ProductRef=jre-6u11-oth-JPR@CDS-CDS_Developer">JRE</a> directly from Sun and install it on their systems. Java Ra should be run after the installation as it will remove all old versions of Java while keeping the latest version installed.</p><p><span id="more-8794"></span><strong>List of vulnerabilities:</strong></p><ul><li>The Java Runtime Environment Creates Temporary Files That Have “Guessable” File Names</li><li>Java Runtime Environment (JRE) Buffer Overflow Vulnerabilities in Processing Image Files and Fonts</li><p>May<li>Allow Applets or Java Web Start Applications to Elevate Their Privileges</li><li>Multiple Security Vulnerabilities in Java Web Start and Java Plug-in May Allow Privilege Escalation</li><li>The Java Runtime Environment (JRE) “Java Update” Mechanism Does Not Check the Digital Signature of the JRE that it Downloads</li><li>A Buffer Overflow Vulnerability in the Java Runtime Environment (JRE) May Allow Privileges to be Escalated</li><li>A Security Vulnerability in the Java Runtime Environment (JRE) Related to Deserializing Calendar Objects May Allow Privileges to be Escalated</li><li>The Java Runtime Environment UTF-8 Decoder May Allow Multiple Representations of UTF-8 Input</li><li>Security Vulnerability in Java Runtime Environment May Allow Applets to List the Contents of the Current User’s Home Directory</li><li>Security Vulnerability in the Java Runtime Environment With Processing RSA Public Keys</li><li>A Security Vulnerability in Java Runtime Environment (JRE) With Authenticating Users Through Kerberos May Lead to a Denial of Service (DoS)</li><li>Security Vulnerabilities in the Java Runtime Environment (JRE) JAX-WS and JAXB Packages may Allow Privileges to be Escalated</li><li>A Security Vulnerability in Java Runtime Environment (JRE) With Parsing of Zip Files May Allow Reading of Arbitrary Memory Locations</li><li>A Security Vulnerability in the Java Runtime Environment may Allow Code Loaded From the Local Filesystem to Access LocalHost</li></ul><p>Users who cannot install the Java update immediately should disable Java for the time being to protect their computer system from the exploits.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/12/07/java-security-update-released/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (user agent is rejected)
Database Caching 6/13 queries in 0.004 seconds using disk

Served from: www.ghacks.net @ 2010-03-19 18:43:10 -->