Advertisement
Promo

Security threats Toolkit

Mac OS X vulnerable to critical Java bug

Matthew Broesma ZDNet.co.uk

Published: 20 May 2009 17:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Apple's Mac OS X is vulnerable to a security flaw in Java that was originally publically disclosed almost six months ago, a security researcher has warned.

The flaw affects a number of platforms running Java, and has been patched by most other operating-system vendors, noted researcher Julien Tinnes in a blog post on Tuesday.

"Unfortunately, it is still not patched in [Apple's] latest security update from just a few days ago," he wrote.

Exploits can be written purely in Java code, meaning they work on multiple platforms, Tinnes said. He recommended that Mac OS X users disable Java in their web browsers.

"This one is a pure Java vulnerability," Tinnes wrote in the post. "This means you can write a 100 percent reliable exploit in pure Java. This exploit will work on all the platforms, all the architectures and all the browsers."

Java is enabled by default in Mac OS X browsers such as Firefox and Safari, and Tinnes said he had successfully exploited the Java bug on both browsers.

Read this

Photos
Photos: Evolution of the Mac

A look at how the Mac has evolved through the years...

Read more +

The bug (designated CVE-2008-5353 in the Common Vulnerabilities and Exposures database) was first reported to Sun in August of last year, and was patched by Sun in December.

It allows a remote attacker to take over a system, and was ranked as "highly critical" by security vendor Secunia.

The vulnerability affects multiple implementations of Java, including OpenJDK, GIJ and icedtea, as well as Sun's own implementation, security researchers said.

Tinnes noted that many companies use web applications that rely on a specific Java version, and that Java updates can break those applications. "This may be the reason why Apple's Java updates are so infrequent," he wrote.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
6 out of 6 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters