After patch, researchers find another Java vulnerability

By
Follow google news

Polish firm Security Explorations claims credit.

Oracle soon may have another Java version 7 unpatched exploit on its hands.

After patch, researchers find another Java vulnerability

Hours after the company that maintains Java released a much-anticipated patch for a widespread malware attack, Polish research outfit Security Explorations said it discovered a new vulnerability in the software platform.

This bug, combined with previous flaws that it has reported to Oracle -- but which have so far gone unfixed -- could lead to a "complete JVM (Java Virtual machine) sandbox bypass in the environment of [the] latest Java SE (Standard Edition) software," Adam Gowdiak, the founder and CEO of Security Explorations, wrote in a Friday post to the Bugtraq mailing list.

His firm has delivered details of the vulnerability, along with a proof-of-concept, to Oracle.

Exploit code relating to the previous vulnerability was leaked which enabled the attack to spread like wildfire.

Despite the patch from Oracle, most experts recommend that users permanently disable Java functionality in the browser. In fact, Microsoft, which makes the world's most heavily used browser, Internet Explorer, is developing a Fix-It tool to allow users to do just that.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Services Australia to tap law enforcement data for staff security

Services Australia to tap law enforcement data for staff security

Researchers detail Bluetooth headphone attack that can hijack smartphones

Researchers detail Bluetooth headphone attack that can hijack smartphones

Patients fret as ManageMyHealth data breach drama plays out

Patients fret as ManageMyHealth data breach drama plays out

Aussie teenager charged with swatting US retailers and educational institutions

Aussie teenager charged with swatting US retailers and educational institutions

Log In

  |  Forgot your password?