VRB News
  • Home
  • About us
  • IT news
  • Tech
  • World
  • Contact
No Result
View All Result
  • Home
  • About us
  • IT news
  • Tech
  • World
  • Contact
No Result
View All Result
VRB News
No Result
View All Result
Home IT news

Old Java-leak appears again

admin by admin
March 20, 2021
in IT news
0
Old Java-leak appears again
0
SHARES
11
VIEWS
Share on FacebookShare on Twitter

A Patch, the Oracle for the leak in Java SE some time ago, had published, seems to be ineffective. Security researchers are now warning that attackers are able to execute leak arbitrary Code.

A well-known vulnerability in the Java SE, seems to be open again. Adam Gowdiak, the CEO of the Polish security provider, Security Explorations reported to Oracle have already been fixed in September 2013 the leak. But the Patch seems to be ineffective. Therefore, it is attackers are able to Code outside the Java Sandbox and execute.

“We have found out that the Oracle Patch can easily deal with it,” writes Gowdiak in a post on the Full Disclosure. Only four characters from the original, in October 2013, published attack code would need to be changed. In addition, a HTTP to Server to respond to a first request to a particular Java class with a “404 (not found)”error message.

Security Explorations provides the updated attack code, and also a detailed description of the vulnerability (PDF). Has been tested with Java SE 7 Update 97, Java SE 8 Update 74 and also the Early Access Build 108 of Java SE 9. Gowdiak, however, indicate that the Click2Play function, which obtains prior to the execution of Java Applets consent of a user is not affected.

If a web page tries to load a vulnerable application outside of the browser, users can get this warning to see (image: Microsoft).If a web page tries to load a vulnerable application outside of the browser, users can get this warning to see. (Image: Microsoft)

The security researchers have informed Oracle in advance about the faulty Patch. As a reason it’s called a new Directive for the disclosure of security vulnerabilities. “Defect Fixes will no longer be tolerated. If we encounter a broken Fix for a vulnerability that we have already been reported to the manufacturer, it is made without notice to the public,” said Gowdiak more.

In addition, Gowdiak criticized Oracle’s valuation of the vulnerability. The company in October of 2013, and that the gap with the identifier CVE-2013-5838 only by using Java Web Start applications and Java could Applets are used. “We have confirmed that an Exploit is also used in a server environment, as well as with the Google App Engine for Java.”

Security Explorations power since the beginning of 2012 on security vulnerabilities in Java attention. The company accuses Oracle to provide Patches as soon as possible. In a presentation at the JavaLand conference in Brühl (PDF) reported to the security researchers of a in September 2012, the reported errors, the Oracle only in January 2013 have fixed. The company have implemented only by Security Explorations, a proposed Fix.

[mit Material von Stefan Beiersmann, ZDNet.de]

Previous Post

Oracle brings unscheduled emergency Patch for a critical vulnerability in the Java SE

Next Post

JavaFX without a future in Oracle?

admin

admin

Related Posts

eBay acquires KnownOrigin and wants to use NFTs and Blockchain more
IT news

eBay acquires KnownOrigin and wants to use NFTs and Blockchain more

June 24, 2022
Half-Life 2 -- Updated for DK2
IT news

Half-Life 2 — Updated for DK2

June 24, 2022
Rotstift markiert Scam
IT news

Risk ticker: BaFin warns of unauthorized transactions of two websites

June 24, 2022
Do cryptocurrencies serve the drug trade? China provides new insight
IT news

Do cryptocurrencies serve the drug trade? China provides new insight

June 24, 2022
Permira and H&F acquire Zendesk for ten billion dollars
IT news

Permira and H&F acquire Zendesk for ten billion dollars

June 24, 2022
Next Post
JavaFX without a future in Oracle?

JavaFX without a future in Oracle?

Premium Content

Split your video files into 2 parts

Split your video files into 2 parts

February 7, 2022
How to use your Oculus Quest 2 to play any virtual reality game for PC wirelessly ” You Cloud

How to use your Oculus Quest 2 to play any virtual reality game for PC wirelessly ” You Cloud

March 13, 2022
Ryg, the new Kickstarter sensation Sent by the community

Ryg, the new Kickstarter sensation Sent by the community

January 6, 2022

Browse by Category

  • Games
  • IT news
  • Tech
  • World
VRB News

VRB News is ready to cooperate with webmasters and content creators. Send an email to info@virtualrealitybrisbane.com

Categories

  • Games
  • IT news
  • Tech
  • World

Recent Posts

  • eBay acquires KnownOrigin and wants to use NFTs and Blockchain more
  • Half-Life 2 — Updated for DK2
  • Risk ticker: BaFin warns of unauthorized transactions of two websites

© 2021 - The project has been developed ServReality

No Result
View All Result
  • Home
  • About us
  • IT news
  • Tech
  • World
  • Contact

© 2021 - The project has been developed ServReality

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?