ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Java mega-update plugs 29 critical security holes

By | October 14, 2010, 9:40am PDT

Summary: According to Oracle, 28 of these vulnerabilities could be remotely exploitable without authentication (over a network without the need for a username and password).

Oracle has issued a massive Java SE and Java for Business update to fix 29 security vulnerabilities that could be exploited to take complete control of vulnerable computers.

According to Oracle, 28 of these vulnerabilities could be remotely exploitable without authentication (over a network without the need for a username and password).  follow Ryan Naraine on twitterThe patches are available for Windows, Linux and Solaris users.   Apple’s Mac OS X is also vulnerable but security updates for that operating system is usually delayed for several months.

According to Oracle’s advisory,  15 of the 29 vulnerabilities carry the maximum 10.0 CVSS severity rating.

Due to the threat posed by a successful attack, Oracle strongly recommends that affected users apply the available patches “as soon as possible.”

You can use use this link to run a quick scan to determine whether the Java environment installation on your machine is up to date.

Windows users should be very careful when applying Java updates.  The company has an annoying history of bundling third-party software (browser toolbars) that are pre-checked by default.

During the installation process, be sure to uncheck any boxes that install software that you don’t need (see screenshot)

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
12
Comments

Join the conversation!

Just In

J , J#, C#
THUFIR.HAWAT 22nd Nov 2010
@ryanstrassburg you're probably correct in the specifics. To clarify my intended meaning: Microsoft isn't against VM's, .NET is a VM.
Do mankind a favor and step on the ugly java bug, it's such an odorous nasty thing!
0 Votes
+ -
Only after you step on...
zkiwi 14th Oct 2010
The ugly beast that is .net, or for that matter flash or [insert any development platform that people have an opinion on here].
0 Votes
+ -
@zkiwi

Agreed. If we 'stomped' on all the 'ugly' programs (in someone's opinion) we wouldn't have any software left.
Believe you will need!!!!!!

is a very good!

come HTTP://0845/4PC
0 Votes
+ -
Heh, a ZDNet blogger telling people not to install a Microsoft product and put a big screenshot of it instead of something more relevant like the Java detection site. No surprise there given ZDNet's bias and all.
0 Votes
+ -
@Loverock Davidson

LD, get some new glasses, preferably ones without `rose colored lenses`.

Please read more carefully:

`You can use use this link to run a quick scan to determine whether the Java environment installation on your machine is up to date.`

I found that as the fifth paragraph in the article. Oh, and BTW, using that link, I found out that the version I was using is out of date (version 6, update 18).
0 Votes
+ -
@fatman65535
Take your own advice and top ignoring the giant picture they put in the blog of a Microsoft product and trying to tell us not to install it.
0 Votes
+ -
LOL
LarsDennert 14th Oct 2010
Why would google steal this code LOL? Why would MS who is totally anti Java bundle their tool bar with Java?
0 Votes
+ -
Why steal the code
THUFIR.HAWAT 14th Oct 2010
@LarsDennert you're an idiot. If Microsoft is anti-Java, then what's J++? (Hint, it was a Microsoft product.) Furthermore, had Sun been more litigious .NET would've been squashed for patent infringement -- just ask Gosling.

As to Google, sure, they "stole" the JVM. Well, actually, they reverse engineered it. That's not disputed.

None of which has anything to do with some crap toolbar.

-Thufir
0 Votes
+ -
Hmmm....
ryanstrassburg 15th Oct 2010
@THUFIR.HAWAT
If I recall correct J++ was discontinued, and last included with Visual Studio 6.0. The .NET framework was being born at hat time around 2000, J++ basically became J# due to questionable practices of MS's deal with SUN for not implementing it as-described by SUN Microsystems. J# is now being phased out as well due to declining usage and only available for support last with VS2005.

Reference:
http://msdn.microsoft.com/en-us/vjsharp/default.aspx
0 Votes
+ -
J , J#, C#
THUFIR.HAWAT 22nd Nov 2010
@ryanstrassburg you're probably correct in the specifics. To clarify my intended meaning: Microsoft isn't against VM's, .NET is a VM.
0 Votes
+ -
Loverock Davidson
stilesalaska 15th Oct 2010
You are Such a Troll! OMG you and Ye!! Are you brothers???

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix