VRB News
Virtual Reality Brisbane
  • Home
  • About us
  • IT news
  • Tech
  • World
  • Contact
No Result
View All Result
  • Home
  • About us
  • IT news
  • Tech
  • World
  • Contact
No Result
View All Result
No Result
View All Result
Home IT news

Old Java-leak appears again

admin by admin
March 20, 2021
in IT news
0
Old Java-leak appears again
0
SHARES
16
VIEWS
Share on FacebookShare on Twitter

A Patch, the Oracle for the leak in Java SE some time ago, had published, seems to be ineffective. Security researchers are now warning that attackers are able to execute leak arbitrary Code.

A well-known vulnerability in the Java SE, seems to be open again. Adam Gowdiak, the CEO of the Polish security provider, Security Explorations reported to Oracle have already been fixed in September 2013 the leak. But the Patch seems to be ineffective. Therefore, it is attackers are able to Code outside the Java Sandbox and execute.

“We have found out that the Oracle Patch can easily deal with it,” writes Gowdiak in a post on the Full Disclosure. Only four characters from the original, in October 2013, published attack code would need to be changed. In addition, a HTTP to Server to respond to a first request to a particular Java class with a “404 (not found)”error message.

Security Explorations provides the updated attack code, and also a detailed description of the vulnerability (PDF). Has been tested with Java SE 7 Update 97, Java SE 8 Update 74 and also the Early Access Build 108 of Java SE 9. Gowdiak, however, indicate that the Click2Play function, which obtains prior to the execution of Java Applets consent of a user is not affected.

If a web page tries to load a vulnerable application outside of the browser, users can get this warning to see (image: Microsoft).If a web page tries to load a vulnerable application outside of the browser, users can get this warning to see. (Image: Microsoft)

The security researchers have informed Oracle in advance about the faulty Patch. As a reason it’s called a new Directive for the disclosure of security vulnerabilities. “Defect Fixes will no longer be tolerated. If we encounter a broken Fix for a vulnerability that we have already been reported to the manufacturer, it is made without notice to the public,” said Gowdiak more.

In addition, Gowdiak criticized Oracle’s valuation of the vulnerability. The company in October of 2013, and that the gap with the identifier CVE-2013-5838 only by using Java Web Start applications and Java could Applets are used. “We have confirmed that an Exploit is also used in a server environment, as well as with the Google App Engine for Java.”

Security Explorations power since the beginning of 2012 on security vulnerabilities in Java attention. The company accuses Oracle to provide Patches as soon as possible. In a presentation at the JavaLand conference in Brühl (PDF) reported to the security researchers of a in September 2012, the reported errors, the Oracle only in January 2013 have fixed. The company have implemented only by Security Explorations, a proposed Fix.

[mit Material von Stefan Beiersmann, ZDNet.de]

Previous Post

Oracle brings unscheduled emergency Patch for a critical vulnerability in the Java SE

Next Post

JavaFX without a future in Oracle?

admin

admin

Related Posts

How to Grow a YouTube Channel with ScaleLab
IT news

How to Grow a YouTube Channel with ScaleLab: Effective Strategies for Creators

February 4, 2025
Sticker mockups
IT news

Sticker mockups: how to visualize your ideas professionally and efficiently

January 13, 2025
Ways to Get Free Senegal Proxies for Work and Surfing
IT news

Ways to Get Free Senegal Proxies for Work and Surfing

December 24, 2024
Crypto Betting Frontiers
IT news

Crypto Betting Frontiers: The 2025 Landscape

December 6, 2024
iGaming Marketing Trends for 2025
IT news

iGaming Marketing Trends for 2025: Adapting to a Rapidly Changing Landscape

December 5, 2024
Next Post
JavaFX without a future in Oracle?

JavaFX without a future in Oracle?

Premium Content

Ethereum Kurs Prognose: 7 Tage Abwärtsbewegung jetzt beendet?

Ethereum price Forecast: 7 days of downward movement now ended?

August 6, 2022
Internet Explorer is history

Internet Explorer is history

June 16, 2022
Bitcoin and Ethereum chart analysis – Sell-off at the start of the week

Bitcoin and Ethereum chart analysis – Sell-off at the start of the week

July 28, 2022

Browse by Category

  • Games
  • IT news
  • Tech
  • World

VRB News is ready to cooperate with webmasters and content creators. Send an email to info@virtualrealitybrisbane.com

Categories

  • Games
  • IT news
  • Tech
  • World

Recent Posts

  • How to Grow a YouTube Channel with ScaleLab: Effective Strategies for Creators
  • Sticker mockups: how to visualize your ideas professionally and efficiently
  • Ways to Get Free Senegal Proxies for Work and Surfing

© 2023 - The project has been developed ServReality

No Result
View All Result
  • Home
  • About us
  • IT news
  • Tech
  • World
  • Contact

© 2023 - The project has been developed ServReality

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?