I would imagine we are going to see more and more of these exploits unless Oracle takes the same approach that Microsoft took, and even then it will be years before the benefits are felt.
I would imagine we are going to see more and more of these exploits unless Oracle takes the same approach that Microsoft took, and even then it will be years before the benefits are felt.
(Not trying to rag on MS.)
... except SELinux.
the flaw would be exploitable on any machine with Java 5,
6, or 7 enabled (whether it’s Windows 7 64-bit, Mac OS X,
Linux, or Solaris
[...]
“An attacker could then install programs, view, change,
or delete data with the privileges of a logged-on user.”
In short, you can rag on modern operating system design because whatever permissions you grant to the Java process (regardless of operating system) are the same permissions which get inherited by the exploit. If you run the Java process under sudo on Linux, then the exploit runs under sudo as well.Taking a guess I would imagine its because the JVM is doing something it shouldn't be, similar to how Adobe products continually have flaws found in them, which isn't the fault of the OS.
If that's the case blaming Microsoft would be like blaming the Linux kernel for being exploited when the actual attack was against a service like Apache running under the root account. Unless you intelligently run things under proper accounts all the OS security in the world won't save you if there is a flaw in something running on it.
One other thing before I go- are other JVM languages affected by these bugs?
Second, the parent wasn't comparing the products but the security practices followed; MS's hardcore security practices are well known and have served them very well over the last decade. The products they make have little to nothing to do with this.
Lastly, the language you use has absolutely nothing to do with this bug -- it's a JVM bug itself.