Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Java flaw poses widespread security threat
CNet News ^ | 13 July 2007 | Liam Tung

Posted on 07/13/2007 10:15:13 AM PDT by ShadowAce

Google's security team has discovered vulnerabilities in the Sun Java Runtime Environment that threaten the security of all platforms, browsers and even mobile devices.

"This is as bad as it gets," said Chris Gatford, a security expert from penetration testing firm Pure Hacking.

"It's a pretty significant weakness, which will have a considerable impact if the exploit codes come to fruition quickly. It could affect a lot of organizations and users," Gatford told ZDNet Australia.

Australia's Computer Emergency Response Team analyst, Robert Lowe, warned that anyone using the Java Runtime Environment or Java Development Kit is at risk.

"Delivery of exploits in this manner is attractive to attackers because even though the browser may be fully patched, some people neglect to also patch programs invoked by browsers to render specific types of content," said Lowe.

According to Gatford, the bugs threaten pretty much every modern device. "Java runs on everything: (mobile) phones, PDAs and PCs. This is the problem when you have a vulnerability in something so modular--it affects so many different devices."

"Also, this exploit is browser-independent, as long as it invokes a vulnerable Java Runtime Environment," Gatford added.

Pure Hacking's Gatford said the problem is compounded by the fact that organizations are unlikely to take on the daunting process of patching all of their Java Runtime vulnerabilities.

"It would be an extremely difficult and laborious process for an organization trying to patch Java Runtime across the enterprise," he said.


TOPICS: Business/Economy; Technical
KEYWORDS: java; vulnerability

1 posted on 07/13/2007 10:15:13 AM PDT by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; PenguinWry; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; ..

2 posted on 07/13/2007 10:15:29 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

BUMP!


3 posted on 07/13/2007 10:19:17 AM PDT by Publius6961 (MSM: Israelis are killed by rockets; Lebanese are killed by Israelis.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: ShadowAce

Now EVERYBODY KNOWS!........


4 posted on 07/13/2007 10:20:22 AM PDT by Red Badger (No wonder Mexico is so filthy. Everybody who does cleaning jobs is HERE!.......)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

The bad guys already know. Now we know enough to protect ourselves.


5 posted on 07/13/2007 10:20:57 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 4 | View Replies]

To: ShadowAce

You know where all of this is gonna lead to, don’t you?.......Some lib dem will eventually call for a Department of Software and Internet Security to be created............


6 posted on 07/13/2007 10:28:06 AM PDT by Red Badger (No wonder Mexico is so filthy. Everybody who does cleaning jobs is HERE!.......)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Red Badger
You know where all of this is gonna lead to, don’t you?.......Some lib dem will eventually call for a Department of Software and Internet Security to be created............

Department of Software and Internet Security = Big SIS...

7 posted on 07/13/2007 10:36:18 AM PDT by danneskjold
[ Post Reply | Private Reply | To 6 | View Replies]

To: danneskjold

Way to go, Ragnar!................


8 posted on 07/13/2007 10:37:46 AM PDT by Red Badger (No wonder Mexico is so filthy. Everybody who does cleaning jobs is HERE!.......)
[ Post Reply | Private Reply | To 7 | View Replies]

To: ShadowAce

So, what do we do? Disable java in Firefox? Or await a new version of java?


9 posted on 07/13/2007 10:50:34 AM PDT by Clara Lou (Fred Thompson, '08-- imwithfred.com)
[ Post Reply | Private Reply | To 2 | View Replies]

To: ShadowAce

When the Java patch gets released, it will probably only successfully install on around 30% of the computers you will try to install it on. lol

I’ve found Java to be extremely buggy, on windows boxes anyway.


10 posted on 07/13/2007 11:36:43 AM PDT by KoRn (Just Say NO ....To Liberal Republicans - FRED THOMPSON FOR PRESIDENT!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: KoRn

It’s not a whole lot better under Linux. I find it rather slow.


11 posted on 07/13/2007 11:44:52 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Clara Lou
So, what do we do? Disable java in Firefox? Or await a new version of java?

It's java, it isn't refered to as 'Write once crash everywhere.' without reason.

12 posted on 07/13/2007 11:50:46 AM PDT by Brellium ("Thou shalt not shilly shally!" Aron Nimzowitsch)
[ Post Reply | Private Reply | To 9 | View Replies]

To: ShadowAce

Apple’s ahead of the curve on this one. The iPhone doesn’t support Java.


13 posted on 07/13/2007 2:31:26 PM PDT by AZLiberty (President Fred -- I like the sound of it.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
Wow, seriously... The article is really terrible. It makes your average user think that just by running Java on a machine that suddenly they are at risk for complete meltdown. However, if you click on the link to the patch and actually read about it, it becomes quickly obvious the flaw is only if you are attempting to process a .gif image with Java.

As a developer, I can tell you that this is rare... Not to mention, you have to be navigating to a website or purposefully running a program that would intentionally exploit this security hole. That puts the threat level back down with almost any other threat you see... *yawn* I'll go back to my dangerous and scary Java programming.

14 posted on 07/16/2007 3:47:07 PM PDT by Kaylee Frye
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson