Java 6 exploit found in the wild
theinquirer.net
theinquirer.net
Right now it's "just" Java 6 which isn't installed on every machine out there (but still on a huge part of all Java capable machines). Next year it will be Windows XP which still has between 40% and 80% usage.
Me personally, I'm really interested how this is going to turn out. Will we see unofficial patches? Will we see anti virus vendors step up and provide semi-official patches? Will vendors have to cave and continue issuing patches? Will the malware issue just be ignored? What kind of damage does need to happen before something changes?
the non-technical managers understand that the FDA only approved the J6 version of the app. If you want to use J7, you have to resubmit to the approval process.
The law is there for a reason.
SOME apps it won't matter... like maybe some billing or hospital transportation apps or something... but certainly anything diagnostic in nature cannot be run in a manner in which it was not approved.
Which is why biomedical engineering and IT are different departments. IT doesn't touch anything that directly touches a patient.
One of the applications I'm talking about is a physician portal meant specifically to be used over the public internet.
Ouch. That just screams 'this company doesn't understand security at all'.
Source?
This might finally be the end of IE6.
AFAIK, Oracle Java 1.6.0 is EOL, and thus does not receive patches in a timely manner (if at all).
1: http://www.oracle.com/technetwork/java/javase/training/index...
OTOH, the Linux openjdk package stays pretty up to date and doesn't install the Ask toolbar ;-).
Make my wonder if there other products may be dangerous too.
Apparently I don't have any software that is depended on it. If I had known I would have uninstalled it a long time ago!
A total nightmare from a security perspective.
They are starting to roll out a version for mobile phones now, but it requires that your operator supports it and many will need a new sim card so it takes time.
In the meantime if you are out with your friend and you finds out you want to see a movie, you will have to walk to the theater or call a friend with a pc to buy a ticket. You can't just do it online from you iPhone (some movie theaters may have a app for that, but not where I currently live :( ).
It feels especially bad because it wasn't always like this. Before the massive adoption of Bank ID you could do almost anything online from your phone.
Norway: https://www.bankid.no/
Sweden: http://www.bankid.com/
The Swedish one uses native apps for Windows, Mac and Linux rather than java. Still trivial to attack from a trojan though.. :/
EDIT: To elaborate on jokc's reply (who appears to be shadowbanned), it seems that this exploit is only a problem for applications that use Java's sandboxing features, and the browser plugin is the best example of this -- but desktop applications can use these features too.
Sandboxes only apply in the browser, as far as I can think of -- Java code all executes in the context of a security manager, but does anyone actually set a custom security manager for running untrusted Java applications? (Maybe I'm just missing an example you know of...)
I'm afraid people do use it; of course the banks and so on (who probably can migrate to better solutions fairly easily); personally, I have a site that's pretty active this time of year, with music theory training applets which can capture MIDI and microphone input in-browser.
I could spend a year to rebuild what I can in JavaScript and HTML5 (there's nothing out there besides Java that'll give me MIDI input, of course), if I had a year to burn, which I don't.
Should I shut down the site entirely (and block thousands of users) because there are security issues appearing in OLD versions of Java, that many browsers don't even let you run anymore? Or should I just encourage browsers to keep refining their control over when applets can run -- so applets can be (again) simple to run by people who actually want them?
I'm leaning towards the latter.
The few who have to use it can keep using the old version and it being deprecated would put pressure on the websites that still use it to stop doing so.
* Go to: about:config
* Search "plugins.click_to_play"
* Enable.
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2463
https://access.redhat.com/security/cve/CVE-2013-2463
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/b79d56eee... -- 4 month old fix
> Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
Doesn't that say Java SE 7 Update 21, as well as OpenJDK 7? Or is that new info since the title was written? HN should update accordingly?
Edit: I'm on 1.6
Why does Java have so many security holes? Is it really worse than any other language, or is it just so ubiquitous that it presents itself as a good target?
Most of these vulnerabilities are only applicable to environments which are required to run untrusted code.
Writing good sandboxes can be hard. Web browsers are pretty good at it but unlike java - they dont also have to support unsandboxed code running on the same VM so that makes things considerably easier.
"Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets."