ie8 fix

Java

Oracle pushes out new Java update to patch security holes

Oracle has rushed out a new Java security patch designed to plug up a range of holes in the software.

The February Critical Patch Update for Java SE addresses 50 security vulnerabilities, 44 of which affect the use of Java as a plug-in for Web browers, according to an Oracle blog posted Friday. If not properly patched, the plug-in could open the door for attackers to remotely execute code on a PC or Mac by directing users to malicious Web sites.

"The popularity of the Java Runtime Environment in desktop browsers, and the fact that Java in browsers is … Read more

Apple updates Java for Snow Leopard following blockage

Following another recent security issue with Java, Apple issued an update that added the latest versions to the system's browser plug-in blacklist to protect users from any potential threats; however, in doing so it silently blocked a number of people from accessing required Java content, such as banking and financial Web sites.

To manage this problem, if you need Java, then the latest version from Oracle (version 1.7.0_13) that was released yesterday should have addressed the security holes and get your system back up and running. You can download it for OS X Lion or Mountain Lion … Read more

XProtect update blocks unpatched Java versions in OS X

Early this morning Apple issued an update to its XProtect malware-handling system in OS X that updates the Web plug-in blacklist to include a more recent version of Oracle's Java plug-in. The update now will prevent all versions of the Java Web plug-in before version 1.7.11.22 from running on the system (previously the limit was version 1.7.10.19).

This change was likely made because of a recent security issue in the prior version of the Java 7 runtime that affected JRE 7 Update 10 and earlier. A patch for this was issued by Oracle … Read more

Firefox to block Silverlight and Java -- but not Flash

To improve security and cut crashes, Firefox will block plug-ins including Microsoft Silverlight, Adobe Reader, Apple's QuickTime and Oracle's Java, Mozilla said.

Only the newest version of Adobe Systems' Flash Player will be run by default, said Michael Coates, Mozilla's director of security assurance, in a blog post yesterday.

Plug-ins extend a browser's ability to run software or handle different media and file formats, but that extra ability opens new avenues for attack. They've been a staple of Web development for years, but browser makers are working hard to reproduce their abilities directly with Web … Read more

Beware of fake Java updates

Following recent security vulnerabilities in Java, malware developers are taking a new approach to exploit the Java platform by issuing false updates that pose as legitimate updates for the runtime.

The latest version of the Java runtime that fixes recent vulnerabilities is update 11, and Kaspersky labs is reporting that a new malware is out that poses as "Java Update 11." The malware is packaged in a Java archive file called "javaupdate11.jar" that contains two Windows-based executables called "up1.exe" and "up2.exe." When installed the programs open a back door … Read more

Do you need to uninstall Java to be safe from its vulnerabilities?

Lately Java has been getting a bit of bad press, thanks to several consecutive security holes that have been exploited by malware developers. One notable occurrence was the Flashback malware threat that affected a number of OS X users, which (though due in part to Apple's negligence about Java upkeep) was rooted in the Java runtime. More recently, Java 7 has seen a new zero-day vulnerability that has been circulating in exploit kits.

In response to these threats, many in the tech community have recommended that people uninstall Java altogether. However, this can be impractical for some, as many … Read more

Homeland Security still advises disabling Java, even after update

Despite an emergency software update issued yesterday by Oracle, the U.S. Department of Homeland Security is still advising computer users to disable Java on their Web browsers, fearing that an unpatched vulnerability remains.

Oracle released a software update on Sunday to address a critical vulnerability in Oracle's Java 7 after the DHS' Computer Emergency Readiness Team issued an advisory last week recommending users disable the cross-platform plugin on systems where it was installed. The flaw could allow a remote, unauthenticated attacker to execute arbitrary code when a vulnerable computer visits a Web site that hosts malicious code designed … Read more

Oracle releases software update to fix Java vulnerability

Oracle released an emergency software update today to fix a security vulnerability in its Java software that could allow attackers to break into computers.

The update, which is available on Oracle's Web site, fixes a critical vulnerability in Oracle's Java 7 that could allow a remote, unauthenticated attacker to execute arbitrary code. The attack can be induced if someone visits a Web site that's been set up with malicious code to take advantage of the hole.

Oracle said the update modifies the way Java interacts with Web applications.

"The default security level for Java applets and … Read more

New malware exploiting Java 7 in Windows and Unix systems

A new Trojan horse called Mal/JavaJar-B has been found that exploits a vulnerability in Oracle's Java 7 and affects even the latest version of the runtime (7u10).

The exploit has been described by Sophos as a zero-day attack since it has been found being actively used in malware before developers have had a chance to investigate and patch it. The exploit is currently under review at the National Vulnerability Database and has been given an ID number CVE-2013-0422, where it is still described as relatively unknown:

"Unspecified vulnerability in Oracle Java 7 Update 10 and earlier allows … Read more

Google revs Chrome for Android with new beta release

Android users who want to live an edgier life now can try a beta version of Chrome.

Google yesterday released the Chrome 25 beta for Android 4.x for smartphones and tablets, a version number in sync with the release for personal computers. Previously, the only option was the stable version of Chrome for Android, which is still way back at version 18.

The Chrome for Android beta is available on the Google Play app store, but only by following that link -- it's not visible in Google Play's search, Google said. The beta version can be installed … Read more