Advertisement
Promo

Security threats Toolkit

Mac OS X vulnerable to critical Java bug

Matthew Broesma ZDNet.co.uk

Published: 20 May 2009 17:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Apple's Mac OS X is vulnerable to a security flaw in Java that was originally publically disclosed almost six months ago, a security researcher has warned.

The flaw affects a number of platforms running Java, and has been patched by most other operating-system vendors, noted researcher Julien Tinnes in a blog post on Tuesday.

"Unfortunately, it is still not patched in [Apple's] latest security update from just a few days ago," he wrote.

Exploits can be written purely in Java code, meaning they work on multiple platforms, Tinnes said. He recommended that Mac OS X users disable Java in their web browsers.

"This one is a pure Java vulnerability," Tinnes wrote in the post. "This means you can write a 100 percent reliable exploit in pure Java. This exploit will work on all the platforms, all the architectures and all the browsers."

Java is enabled by default in Mac OS X browsers such as Firefox and Safari, and Tinnes said he had successfully exploited the Java bug on both browsers.

Read this

Photos
Photos: Evolution of the Mac

A look at how the Mac has evolved through the years...

Read more +

The bug (designated CVE-2008-5353 in the Common Vulnerabilities and Exposures database) was first reported to Sun in August of last year, and was patched by Sun in December.

It allows a remote attacker to take over a system, and was ranked as "highly critical" by security vendor Secunia.

The vulnerability affects multiple implementations of Java, including OpenJDK, GIJ and icedtea, as well as Sun's own implementation, security researchers said.

Tinnes noted that many companies use web applications that rely on a specific Java version, and that Java updates can break those applications. "This may be the reason why Apple's Java updates are so infrequent," he wrote.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
6 out of 6 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

2 comments

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters