ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Sun says Java flaw has been patched

Robert Vamosi CNET News.com

Published: 13 Jul 2007 09:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

UPDATE: Sun says a Java security threat, the subject of an earlier Australian report, has been patched.

A news story from ZDNet Australia based on a CERT advisory identified vulnerabilities within Sun's Java Runtime Environment. However, Sun representatives said the company has already patched the flaws and that there are no known exploits circulating in the wild.

Sun on Friday released a new version of Java SE 6 Update 2 that it says addresses all current vulnerabilities.

The Australian CERT advisory published on Thursday, an update of an original advisory posted on 4 June, summarises two Java Runtime Environment vulnerabilities and also provides links to Sun's patches.

The Java Runtime Environment vulnerabilities cited in the article were first reported by Chris Evans of Google's security team in October. He reported them to Sun, then to the public on 15 May.

One flaw demonstrated in Evans's advisory shows an integer overflow in a Jpeg image. Documented in CVE-2006-2788, this affects Sun Java Development Kit (JDK) before versions 1.5.0_11-b03, 1.6.x and 1.6.0_01-b06.

A second demo shows a local file being opened via the BMP image parser. This was documented in CVE-2006-2789 and affects Sun Java Development Kit (JDK) before versions 1.5.0_11-b03, 1.6.x and 1.6.0_01-b06 on Unix and Linux systems.

Sun spokeswoman Jacki DeCoster recommends that consumers go to Java.com and download Java SE 6 update 2, installing the latest version of the Java Runtime Environment. Additional information about the specific patches related to these vulnerabilities can be found on the company's SunSolve site.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
21 out of 31 people found this useful



Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Java and C++ Developer / Investment Bank / Derivatives -URGENT

I am looking for an excellent Java and C++ Developer to work for a Top Tier Investment Bank Urgently. Understanding of Yolus would be very desirable, ...

Java: Swing over with SQL 30,000-40,000 North West

JAVA Developer required to make modifications to the existing software design for a customer information system that interfaces with a realtime ...

Java / J2EE Developer needed at Global IT services Company- London

They are now looking for a Java / J2EE developer to join their team working on building patches for applications and working on projects with the ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment