On mySimon: Peg Perego John Deere Utility Tractor
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Nov 29, 2005 8:25:00 PM

Sun Microsystems has fixed five security bugs in Java that expose computers running Windows, Linux and Solaris to hacker attack.

The flaws are "highly critical," according to an advisory from Secunia posted Tuesday. Vulnerabilities that get that ranking--one notch below "extremely critical," the security monitoring company's most severe rating--typically open the door to a remote intruder and to full compromise of the system.

All the flaws affect the Java Runtime Environment, or JRE, in computers loaded with Microsoft Windows, Linux or Sun's own Solaris operating system. This is the software many computer owners have on their system to run Java applications. The bugs could allow an intruder to use a Java application to inappropriately read and write files, or to run code on a victim's computer, Sun said in three separate security advisories released late Monday.

The vulnerabilities also affect specific versions of the Sun Java Software Development Kit (SDK) and Java Development Kit (JDK), according to those advisories.

The French Security Incident Response Team, or FrSIRT, rated the issues "critical" in an alert posted Tuesday.

There have been no reported cases of the flaws being exploited by hackers, Sun said in a statement.

Three of the bugs lie in application programming interface, or API, parts of the Java Runtime Environment. Another vulnerability lies in the Java Management Extensions implementation in the software. The fifth flaw is in an unspecified part of the JRE.

Sun, based in Santa Clara, Calif., is urging people to install updated software to protect their systems. It has released updates to address the issues, including JDK and JRE 5.0 Update 4, which was actually delivered on June 23. A newer version, Update 5, was issued in September, but Sun would not say if additional security problems were fixed in that release. The software can be downloaded from the Sun Java Web site.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 70 Talkback(s)
Don't we have enough bigfoots ?
Adds another bigfoot for updates.
Don't we have enough bigfoots ?
Microsoft used to handle fixes, Sun needs recognition and to be famous.... (Read the rest)
Posted by: tedman Posted on: 12/07/05 You are currently: a Guest | | Terms of Use
I'll stick with plain Linux!  Linux Geek | 11/29/05
I'll just leave my computer turned off!  LeeW274 | 11/29/05
What about perl, python, shell/bash?  rcasha_z | 11/29/05
What about perl, python, shell/bash?  rcasha_z | 11/29/05
Another one for the good guys...  Mike Cox | 11/29/05
Ok ... tell us ...  Linux_4u! | 11/29/05
Yep the good guys will plug those holes ....  craig@... | 11/29/05
To celebrate to much mike  I'm Ye, the MS SHILL . | 11/29/05
Kids, kids, kids...  pz0r56 | 11/30/05
8.5!  Sxooter_z | 11/30/05
I don't get it  IceTheNet@... | 11/30/05
This will clear things up.  osreinstall | 11/30/05
So much for the Java "sandbox"  jinko | 11/29/05
More like quicksand!  osreinstall | 11/29/05
Pathetic  ITTech001 | 11/29/05
This news is 2 internet years old  mighetto | 11/29/05
What the....?  JohnLee_z | 11/29/05
apparently those GENIUSes at  Jack-Booted EULA | 11/29/05
Same reason they talk about a Windows exploit  Confused by religion | 11/29/05
heh  JohnLee_z | 12/02/05
What Update if you just want to update?  dragon@... | 11/29/05
no clue as to what version is installed  wackoae | 11/29/05
DOH!  Jeff Spicoli | 11/29/05
Not so smart  DrDoug018 | 11/30/05
who's the amateur?  rcasha_z | 11/29/05
Java Update  pris_z | 11/30/05
Java Update  pris_z | 11/30/05
What Update if you just want to update?  Dreamer.fithp | 11/30/05
I stopped using java eons ago.  kraterz | 11/29/05
You can always tell...  dtaubler | 11/29/05
I'm Willing To Learn  PMC-CON | 11/29/05
Does anyone write desktop apps in Java?  wackoae | 11/29/05
Desktop apps in Java  pierrejvr | 11/29/05
Sure.  Haterock Davidsfather | 11/30/05
Are you?  jalexoid | 11/30/05
Java is OK for distributed/web apps  michael_t | 11/29/05
Different experiences  rcasha_z | 11/29/05
Different Experiences  DanielHolley | 11/30/05
Different Experiences  jalexoid | 11/30/05
Java not ready for prime time  RimaDog@... | 11/29/05
COBOL exploits  Mr. Big | 11/29/05
That's because COBOL is dead  rcasha_z | 11/29/05
COBOL is dead? Has been for ages?  IT Scion | 11/30/05
More COBOL?!  papatator | 11/30/05
More COBOL?!  papatator | 11/30/05
And the problem is ?  michael_t | 11/29/05
The Problem is Attack Surface / Parallel Installations  PMC-CON | 11/29/05
APC and Java  pris_z | 11/30/05
Uh, huh...  bixbyru@... | 11/29/05
I am glad I got an older version o  jackie40d@... | 11/29/05
Could be less secure  rcasha_z | 11/29/05
could be lesssecure and ... slower  PhilippeV | 12/01/05
could be lesssecure and ... slower  PhilippeV | 12/01/05
Old news  CobraA1 | 11/29/05
more ZDNet junk journalism  Jeff Spicoli | 11/29/05
Thank Janet Reno  Waylon May | 11/29/05
There are no holes in Java  Boot_Agnostic | 11/30/05
Cobol not dead  Bragueton | 11/30/05
So why is OS X not affected?  baggins_z | 11/30/05
That remains to be seen.  Haterock Davidsfather | 11/30/05
Follow-up  Haterock Davidsfather | 12/03/05
OS X not effected because it's not Sun  PhilippeV | 12/01/05
Write once.....  SQLServer | 11/30/05
I don't care  zmud | 11/30/05
Joris Evers, CNET News.com  dguith@... | 11/30/05
Joris Evers, CNET News.com  dguith@... | 11/30/05
Java is best served in a coffee cup or thermos  Boot_Agnostic | 11/30/05
Java does not matter anyway  jfreedle2@... | 12/02/05
Don't we have enough bigfoots ?  tedman | 12/07/05
Don't we have enough bigfoots ?  tedman | 12/07/05

What do you think?

advertisement
advertisement
Click Here

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More