Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Java Runtime Environment - Critical Security Patch

This is installed on my work PCs and the update went well.  There was an option to install the Google toolbar that occurred.  Folks should carefully read EULAs and other options presented carefully as they update any software.

Java Runtime Environment - Critical Security Patch
http://sunsolve.sun.com/search/printfriendly.do?assetkey=1-26-102934-1
http://www.f-secure.com/weblog/archives/archive-072007.html#00001231

QUOTE: A buffer overflow vulnerability in the image parsing code in the Java Runtime Environment may allow an untrusted applet or application to elevate its privileges. For example, an applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet.  A second vulnerability may allow an untrusted applet or application to cause the Java Virtual Machine to hang.