HomeSpacer
TV
Spacer
MOVIES
Spacer
MUSIC
Spacer
FASHION
Spacer
GEEKS
Spacer
BOOKS
Spacer
ART
Spacer
COMEDY
Spacer
DANCE
Spacer
CLASSICAL
Spacer
OPERA
Spacer
TRAVEL
Spacer
FITNESS
Spacer
THEATER
 
 LOG IN | REGISTER NOW!

GEEKS TODAY
TOP TOPICS
TOP MOBILE APPS
ABOUT US

Homeland Security Issues Java Warning; Recommends Disabling Completely


Related: Security, Java

Homeland Security Issues Java Warning; Recommends Disabling Completely

The CERT Program has released Vulnerability Note VU#625617 to address a vulnerability in Oracle Java Runtime Environment (JRE) 7 and earlier that is currently being exploited in the wild. This vulnerability may allow an attacker to execute arbitrary code on vulnerable systems.

US-CERT encourages users and administrators to review the Vulnerability Note VU#625617. This advisory includes possible workarounds that help mitigate the risk against known attack vectors by disabling Java in web browsers.

The Oracle Java Runtime Environment (JRE) 1.7 allows users to run Java applications in a browser or as standalone programs. Oracle has made the JRE available for multiple operating systems.

The Java JRE plug-in provides its own Security Manager. Typically, a web applet runs with a security manager provided by the browser or Java Web Start plugin. Oracle's document states, "If there is a security manager already installed, this method first calls the security manager's checkPermission method with aRuntimePermission("setSecurityManager") permission to ensure it's safe to replace the existing security manager. This may result in throwing a SecurityException".

By leveraging unspecified vulnerabilities involving Java Management Extensions (JMX) MBean components andsun.org.mozilla.javascript.internal objects, an untrusted Java applet can escalate its privileges by calling the the setSecurityManager() function to allow full privileges, without requiring code signing. Oracle Java 7 update 10 and earlier are affected.

This vulnerability is being attacked in the wild, and is reported to be incorporated into exploit kits. Exploit code for this vulnerability is also publicly available.

Impact

By convincing a user to visit a specially crafted HTML document, a remote attacker may be able to execute arbitrary code on a vulnerable system.

Solution

We are currently unaware of a practical solution to this problem. Please consider the following workarounds:

Disable Java in web browsers

Starting with Java 7 Update 10, it is possible to disable Java content in web browsers through the Java control panel applet. Please see the Java documentation for more details.
Note: Due to what appears to potentially be a bug in the Java installer, the Java Control Panel applet may be missing on some Windows systems. In such cases, the Java Control Panel applet may be launched by finding and executingjavacpl.exe manually. This file is likely to be found in C:Program FilesJavajre7in or C:Program Files (x86)Javajre7in.
Also note that we have encountered situations where Java will crash if it has been disabled in the web browser as described above and then subsequently re-enabled. Reinstalling Java appears to correct this situation.


Leave Comments

Related Links
Scoop: NCIS: LOS ANGELES on CBS - Tuesday, June 11, 2013Scoop: NCIS: LOS ANGELES on CBS - Tuesday, June 11, 2013
by TV Scoop - May 21, 2013
ABC Studios Announce New 2013-2014 Series OrdersABC Studios Announce New 2013-2014 Series Orders
May 21, 2013
Giovanna Sardelli to Direct Barrington Stage's World Premiere of MUCKRAKERS, 6/13-7/6Giovanna Sardelli to Direct Barrington Stage's World Premiere of MUCKRAKERS, 6/13-7/6
May 21, 2013
Google Unveils Chrome 27, Featuring Faster Page Loads & MoreGoogle Unveils Chrome 27, Featuring Faster Page Loads & More
May 21, 2013
United Airlines Unveils a New Look in Celebration of 25 Years at Newark Terminal C, Region's Original Airline HubUnited Airlines Unveils a New Look in Celebration of 25 Years at Newark Terminal C, Region's Original Airline Hub
May 21, 2013

Past Articles by This Author:
  • Twitter Patents Twitter
  • Amazon.com Goes Down, Internet Briefly Explodes - Were They HACKED?
  • Electronic Arts Reports Q3 FY13 Financial Results; 6 of the Top 20 Titles & Number 1 for iOS Games
  • Amazon.com Announces Fourth Quarter Sales up 22% to $21.27 Billion but Profit Down 45% to 97 Million
  • Open BWW Positions: Writers + Interactive Sales Executive
  • Wii U and Nintendo 3DS Announce Upcoming Release Calendar
  • Homeland Security STILL Recommends Disabling Java Even After Patching
  • New Gartner Report Shows PC Sales Down 4.9% - Blames Tablets
  • Homeland Security Issues Java Warning; Recommends Disabling Completely
  • Feld Motor Sports Teams up with Walmart to Bring Monster Jam Special Value Experiences to Fans Nationwide

    More Articles by This Author...

  • Get News & Specials!

    FLIPBOARD
    SAMSUNG
    APPLE
    GOOGLE
    TUMBLR
    VERIZON
    BELKIN
    PANASONIC
    NETFLIX
    T-MOBILE

    CBS HBO GAMING ACCESSORIES DISNEY SMASH CLOUD MOBILE ABC IPHONE

    Apple's Latest Milestone: App Store Hits 50 Billion Downloads APPLE Apple's Latest Milestone: App Store Hits 50 Billion Downloads
    Google Tells Microsoft to Remove Ad-Less YouTube App from Windows Phones GOOGLE Google Tells Microsoft to Remove Ad-Less YouTube App from Windows Phones
    Breaking News: Surprising No One, Yahoo! Has JUST Bought Tumblr for $1.1 BILLION Dollars TUMBLR Breaking News: Surprising No One, Yahoo! Has JUST Bought Tumblr for $1.1 BILLION Dollars
    Apple and Sony iRadio Negotiations Stymied by Song-Skipping APPLE Apple and Sony iRadio Negotiations Stymied by Song-Skipping
    Google TV to Receive Android Jelly Bean OS Upgrade LG ELECTRONICS Google TV to Receive Android Jelly Bean OS Upgrade
    Spike TV to Air Live Reveal of New Xbox Today SPIKE TV Spike TV to Air Live Reveal of New Xbox Today
    RunKeeper Hits Pebble Smart Watch Today on iPhone and Android RunKeeper Hits Pebble Smart Watch Today on iPhone and Android

    BWW TV World Logo
      
    BWW Movies World Logo
      
    BWW Fashion World Logo
      
    BWW Music World Logo
    BroadwayWorld.com Logo
      
    BWW Opera World Logo
      
    BWW Dance World Logo
      
    BWW Classical World Logo

    All Materials Copyright 2013 Wisdom Digital Media | Privacy Policy | RSS/XMLFeeds