We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
80,259 News Articles

Five new flaws found in the latest version of Java

A week after disclosing two Java vulnerabilities, a Polish security firm reported finding five more in the latest version of Java. When used together, the new holes could bypass the technology's sandbox in order to install malware.

Security Explorations notified Oracle Monday of the vulnerabilities in Java SE 7 Update 15. Along with details of the flaws, Security Explorations also supplied proof of concept code.

Oracle did not respond to a request for comment.

Separately, the flaws do not pose a security problem, the company said. However, when linked together, they can enable someone to bypass the Java's anti-exploit sandbox technology. Security Explorations said it had not seen the vulnerabilities exploited in the wild.

The latest vulnerability report follows a week after the same company reported two other holes in Oracle's latest plug-in used to run Java applications in a browser.

Oracle shipped Java SE 7 Update 15 on Feb. 19, bundling patches released Feb. 1 in an emergency update fixing five other flaws. The next regularly scheduled update is April 16.

The latest discovery came after Oracle rejected one of the bugs Security Explorations reported Feb. 25. "It made us look into Java SE 7 code and its docs once again, gathering counterargument material," Adam Gowdiak, chief executive of the company, said in a post on SecLists.org.Ã'Â

Two of the vulnerabilities could also affect Java SE 6, Gowdiak said. "But since all of the issues need to be combined together to gain a successful Java SE security compromise, we treat it as affecting Java SE 7 only."

[Also see: Oracle's Java security update lacking, experts say]

In releasing the Java SE 7 update this month, Oracle said that it would speed up its patching cycle for Java, which has suffered a significant number of exploitations in the wild through zero-day vulnerabilities. A zero-day flaw is one that has yet to be patched by the software vendor.

"Oracle's intent is to continue to accelerate the release of Java fixes, particularly to help address the security worthiness of the Java Runtime Environment in desktop browsers," Eric Maurice, Oracle's director of software assurance, said in a blog post.Ã'Â

Oracle had released Java updates every four months. Under the new schedule, it will ship updates every two months.

For months, security experts have recommended that people disable Java in all browsers, since only a small number of websites still used the application platform. In those rare cases when Java is needed to run a specific application, experts recommend dedicating one browser for that single purpose.

Read more about application security in CSOonline's Application Security section.


IDG UK Sites

iPad mini 3 vs iPad mini 2 comparison: New iPad mini 3 isn't worth £80 more

IDG UK Sites

Why you shouldn't buy the iPad mini 3: No wonder Apple gave it 10 seconds of stage time

IDG UK Sites

Halloween Photoshop tutorials: 13 masterclasses for horrifying art, designs and type

IDG UK Sites

Should I upgrade from Mavericks to OS X 10.10 Yosemite? What you need to know before updating to...