Oracle will fix Java flaw next month

By
Follow google news

New hole bypasses Java Virtual Machine sandbox.

Oracle will fix a recently discovered vulnerability in Java in its October patch run according to researchers who found the flaw. 

Oracle will fix Java flaw next month

Security firm Security Explorations discovered the new vulnerability, which, when combined with other still-unpatched weaknesses in Java, could allow for a complete bypass of the Java Virtual Machine sandbox in the environment of the latest Java SE software.

Researchers reported the new vulnerability to Oracle a day after the database giant released its 30 August out-of-band patch for holes affecting Java for the browser.

One of those exploits was added to the BlackHole crimeware kit and was being used in widespread attacks.

Some researchers worry this vulnerability could meet the same fate, but so far, no reports of active attacks have emerged.

Oracle confirmed the bug on Monday and promised to address the issue in the 16 October scheduled Java update, Security Explorations said.

An Oracle spokesman did not respond to a request for comment.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Tasmanian gov agencies impacted by cyber attack

Tasmanian gov agencies impacted by cyber attack

Australian chief at US defence contractor L3Harris sold exploits to Russia

Australian chief at US defence contractor L3Harris sold exploits to Russia

Vic gov agencies flying blind on server security, audit finds

Vic gov agencies flying blind on server security, audit finds

Home Affairs streamlines risk vetting for gov tech suppliers

Home Affairs streamlines risk vetting for gov tech suppliers

Log In

  |  Forgot your password?