Print

Advance Notice: Security Updates for Java SE

Sign in
Sign in to post messages.
Latest post 11/04/2009 10:03 AM by ky331. 13 replies.
Page 1 of 1  
Dublin - Ireland
Joined on 08/06/2007
Posts: 742
Points 6,540

Advance Notice: Security Updates for Java SE

The Sun Security Blog published the following update announcement:

"On November 3, 2009, Sun will release the following security updates:
  • JDK and JRE 6 Update 17
  • JDK and JRE 5.0 Update 22
  • SDK and JRE 1.4.2_24
  • SDK and JRE 1.3.1_27
The following Sun Alerts corresponding to these updates will be released following the availability of these updates.
  • 269868
  • 269869
  • 269870
  • 270474
  • 270475
  • 270476"

 

Sun Security Blog


  • Post Points: 50

13 Replies:

Joined on 02/11/2006
Posts: 17,272
Points 65,992

Re: Advance Notice: Security Updates for Java SE

I get a 404 at that link. Nothing new posted at Sun yet. Maybe a time zone issue.


Microsoft MVP - Consumer Security

Member of Alliance of Security Analysis Professionals

SpywareHammer

 

Free Internet Security - WOT Web of Trust

 

  • Post Points: 20
NYC
Joined on 02/11/2001
Posts: 8,842
Points 13,859

Re: Advance Notice: Security Updates for Java SE

NOW AVAILABLE:

Java Runtime Environment (JRE) 6 update 17

This release contains fixes for one or more security vulnerabilities.

http://java.com/en/download/manual.jsp

it's probably safest to go for the OFFLINE (15.9 Meg) update

 

 

Release Notes:  

http://java.sun.com/javase/6/webnotes/6u17.html

-----------

 

Please note:  

This update will automatically remove updates of JRE 6 numbered 10 and higher.

But any older versions of Java have to be uninstalled, separately, before or after the newest installation

 


Free Internet Security - WOT Web of Trust       Use OpenDNS

  • Post Points: 50
Joined on 02/11/2006
Posts: 17,272
Points 65,992

Re: Advance Notice: Security Updates for Java SE

Finally!  Thank you, ky331! Smile


Microsoft MVP - Consumer Security

Member of Alliance of Security Analysis Professionals

SpywareHammer

 

Free Internet Security - WOT Web of Trust

 

  • Post Points: 20
NYC
Joined on 02/11/2001
Posts: 8,842
Points 13,859

Re: Advance Notice: Security Updates for Java SE

Concerning the Java update, please note:   If you are using:


Free Internet Security - WOT Web of Trust       Use OpenDNS

  • Post Points: 20
Joined on 02/11/2006
Posts: 17,272
Points 65,992

Re: Advance Notice: Security Updates for Java SE

I was offered the Bing Toolbar with that one. Indifferent  Although a Bing fan, I declined.


Microsoft MVP - Consumer Security

Member of Alliance of Security Analysis Professionals

SpywareHammer

 

Free Internet Security - WOT Web of Trust

 

  • Post Points: 20
NYC
Joined on 02/11/2001
Posts: 8,842
Points 13,859

Re: Advance Notice: Security Updates for Java SE

BB,

I was just about to make the same comment, about Java offering me the Bing Toolbar (for IE) on this machine... i did NOT have that happen earlier today on another system.


Free Internet Security - WOT Web of Trust       Use OpenDNS

  • Post Points: 5
NYC
Joined on 02/11/2001
Posts: 8,842
Points 13,859

Re: Advance Notice: Security Updates for Java SE

in reference to the Java update:

for those who run Spybot's TeaTimer, and have the updates dated 2009-10-28,

be advised there is  (apparently)  a false-positive there --- which was corrected the following day, 2009-10-29 ---

this F/P will intercept  zipper.exe , a component in the Java installation, as being fraud.softcop.

To fix this, before installing Java, you should:

1) Update Spybot again, to obtain updates dated 2009-10-29 (or later).

2) Reboot your system (so that TeaTimer will restart, and access the new update file).

3) And then, you should be able to install the new Java without TeaTimer interfering.

 

------------------

Since I was unaware about the F/P at the time I installed Java, and being unsure what TeaTimer's improper interaction might have done, I decided to play it safe, by uinstalling Java, and then applying the 3 steps above, to guarantee a clean installation.

 

 


 

 

 


Free Internet Security - WOT Web of Trust       Use OpenDNS

  • Post Points: 20
Joined on 02/11/2006
Posts: 17,272
Points 65,992

Re: Advance Notice: Security Updates for Java SE

My second computer I updated about an hour ago, but I used this link:
http://java.sun.com/javase/downloads/index.jsp

No toolbar offered from this one.


Microsoft MVP - Consumer Security

Member of Alliance of Security Analysis Professionals

SpywareHammer

 

Free Internet Security - WOT Web of Trust

 

  • Post Points: 20
NYC
Joined on 02/11/2001
Posts: 8,842
Points 13,859

Re: Advance Notice: Security Updates for Java SE

Here's more info on this Java update, as copied/pasted from http://secunia.com/advisories/37231/ :

Description:
A weakness and some [highly critical] vulnerabilities have been reported in Sun Java, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or compromise a user's system.

1) A weakness is caused by the update mechanism failing to update JRE to a new version when running on non-English Windows versions.

2) An error in the JRE Deployment Toolkit on Windows can be exploited to execute arbitrary code when viewing a specially crafted web page.

3) An error in the Java Web Start installer can be exploited to run a malicious Java Web Start application as trusted and executed arbitrary code.

4) An unspecified error when processing audio or image files can be exploited to potentially execute arbitrary code via an untrusted applet.

5) Another unspecified error when processing audio or image files can be exploited to potentially execute arbitrary code via an untrusted applet.

6) Two unspecified errors when processing audio or image files can be exploited to potentially execute arbitrary code via an untrusted applet.

7) Three unspecified errors when processing audio or image files can be exploited to potentially execute arbitrary code via an untrusted applet.

8) An unspecified error when processing audio or image files can be exploited to potentially execute arbitrary code via an untrusted applet.

9) An error when verifying HMAC digests can be exploited to potentially bypass authentication via a fake digital signature that is incorrectly accepted as valid by a Java application.

10) An error when decoding DER encoded data can be exploited to exhaust all available JRE memory.

11) An error when parsing HTTP headers can be exploited to exhaust all available JRE memory.

Solution:
Update to a fixed version.

JDK and JRE 6 Update 17:
http://java.sun.com/javase/downloads/index.jsp

--------------------------------------------------------------------------------------

for users of Win98/ME (or for users who, for whatever their reason, want to stick with version 5.0):  JDK and JRE 5.0 Update 22:
http://java.sun.com/javase/downloads/index_jdk5.jsp

Note:   Update 22 will be the last publicly available release of J2SE 5.0;  J2SE 5.0 has reached its End of Service Life


Free Internet Security - WOT Web of Trust       Use OpenDNS

  • Post Points: 20
Caracas, Vnzl.
Joined on 07/07/2007
Posts: 194
Points 3,949

Re: Advance Notice: Security Updates for Java SE

Hi ky 331.

Thank you for the heads up.

" Description:
A weakness and some [highly critical] vulnerabilities have been reported in Sun Java, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or compromise a user's system. "

-------------------------------------------

" Solution:
Update to a fixed version.

JDK and JRE 6 Update 17:
http://java.sun.com/javase/downloads/index.jsp "

I downloaded JRE 6 Update 17 from Java´s web page (Spanish version) and installed it off line last night and it came out as 1.6.0_17b04. Does that mean I do not need the update fix mentioned above by you ? Read this please:

http://java.sun.com/javase/6/webnotes/6u17.html

BTW I was not offered the Bing Toolbar either.

Edit: 17

 


Hernan.


Dimension9200/XPS 410, Win XP Pro._x86. SP3, IE 8 & FF 3.5.5, E6600 2.4GHz, 2GB RAM

Avast 4.8, CIS 3.13(firewall/D+), SpySweeper 6.1, WinPatrol Plus, WOT.

 


"We are all ignorant, but we don't all ignore the same things..." Albert Einstein

 

"When you've excluded the impossible, whatever remains, however improbable, must be the truth..." Sherlock Holmes.

 

 

  • Post Points: 20
NYC
Joined on 02/11/2001
Posts: 8,842
Points 13,859

Re: Advance Notice: Security Updates for Java SE

Hernan wrote:  "it came out as 1.6.0_b04".

Please double check carefully, it should be 1.6.0_17-b04 ; if so, you're okay.


Free Internet Security - WOT Web of Trust       Use OpenDNS

  • Post Points: 20
Caracas, Vnzl.
Joined on 07/07/2007
Posts: 194
Points 3,949

Re: Advance Notice: Security Updates for Java SE

UUPSS.

My bad, mea culpa, I missed the 17. Thank you ky331.

 


Hernan.


Dimension9200/XPS 410, Win XP Pro._x86. SP3, IE 8 & FF 3.5.5, E6600 2.4GHz, 2GB RAM

Avast 4.8, CIS 3.13(firewall/D+), SpySweeper 6.1, WinPatrol Plus, WOT.

 


"We are all ignorant, but we don't all ignore the same things..." Albert Einstein

 

"When you've excluded the impossible, whatever remains, however improbable, must be the truth..." Sherlock Holmes.

 

 

  • Post Points: 20
NYC
Joined on 02/11/2001
Posts: 8,842
Points 13,859

Re: Advance Notice: Security Updates for Java SE

You're welcome.


Free Internet Security - WOT Web of Trust       Use OpenDNS

  • Post Points: 5
Page 1 of 1