We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
80,259 News Articles

Five new flaws found in the latest version of Java

A week after disclosing two Java vulnerabilities, a Polish security firm reported finding five more in the latest version of Java. When used together, the new holes could bypass the technology's sandbox in order to install malware.

Security Explorations notified Oracle Monday of the vulnerabilities in Java SE 7 Update 15. Along with details of the flaws, Security Explorations also supplied proof of concept code.

Oracle did not respond to a request for comment.

Separately, the flaws do not pose a security problem, the company said. However, when linked together, they can enable someone to bypass the Java's anti-exploit sandbox technology. Security Explorations said it had not seen the vulnerabilities exploited in the wild.

The latest vulnerability report follows a week after the same company reported two other holes in Oracle's latest plug-in used to run Java applications in a browser.

Oracle shipped Java SE 7 Update 15 on Feb. 19, bundling patches released Feb. 1 in an emergency update fixing five other flaws. The next regularly scheduled update is April 16.

The latest discovery came after Oracle rejected one of the bugs Security Explorations reported Feb. 25. "It made us look into Java SE 7 code and its docs once again, gathering counterargument material," Adam Gowdiak, chief executive of the company, said in a post on SecLists.org.Ã'Â

Two of the vulnerabilities could also affect Java SE 6, Gowdiak said. "But since all of the issues need to be combined together to gain a successful Java SE security compromise, we treat it as affecting Java SE 7 only."

[Also see: Oracle's Java security update lacking, experts say]

In releasing the Java SE 7 update this month, Oracle said that it would speed up its patching cycle for Java, which has suffered a significant number of exploitations in the wild through zero-day vulnerabilities. A zero-day flaw is one that has yet to be patched by the software vendor.

"Oracle's intent is to continue to accelerate the release of Java fixes, particularly to help address the security worthiness of the Java Runtime Environment in desktop browsers," Eric Maurice, Oracle's director of software assurance, said in a blog post.Ã'Â

Oracle had released Java updates every four months. Under the new schedule, it will ship updates every two months.

For months, security experts have recommended that people disable Java in all browsers, since only a small number of websites still used the application platform. In those rare cases when Java is needed to run a specific application, experts recommend dedicating one browser for that single purpose.

Read more about application security in CSOonline's Application Security section.

IDG UK Sites

Best camera phone of 2015: iPhone 6 Plus vs LG G4 vs Galaxy S6 vs One M9 vs Nexus 6

IDG UK Sites

In defence of BlackBerrys

IDG UK Sites

Why we should reserve judgement on Apple ditching Helvetica in OS X/iOS for the Apple Watch's San...

IDG UK Sites

Retina 3.3GHz iMac 27in preview: Apple cuts £400 of price of Retina iMac with new model