Secunia SmallBusiness
About us
Careers
Memberships
Newsroom
Contact us
Blog
News
Articles

Oracle Java Critical Vulnerability Affects Most Users

Get this blog as an RSS Feed
13:56 CET on the 12th April 2010
Entry written by Alin Rad Pop.

The JRE (Java Runtime Environment) update released by Oracle at the end of March covered 20 vulnerabilities, some of which were marked "Highly critical" by Secunia. You may have the feeling of your system being more secure after applying that update, but few users probably expected that another "Highly critical" vulnerability would become public soon after.

Today, Secunia issued SA39260. This advisory covers a vulnerability in a number of browser plugins installed by default with JRE, commonly termed the Java Deployment Toolkit. The vulnerability was independently reported by Tavis Ormandy and Ruben Santamarta; both providing good descriptions of the problem. Basically, a call to CreateProcessA() is issued by the Java Deployment Toolkit without sanitising command line arguments. This further allows injecting arbitrary JVM arguments and execute code in a privileged context, leading to a complete system compromise when visiting a web site.

This vulnerability is particularly interesting for an attacker as in-depth memory protection mechanisms on modern Windows operating systems such as DEP (Data Execution Prevention) and ASLR (Address Space Layout Randomization) provide no mitigation. Consequently, we expect to soon see attempts to exploit this vulnerability in the wild.

We hope that Oracle decides to provide an update soon. Meanwhile, Java users are recommended to delete or restrict access to all deployment plugins and set the kill-bit for affected ActiveX controls.

Stay Secure,

Alin Rad Pop,
Senior Security Specialist

Discuss this blog entry
A new thread in our forum is created. Activate the thread by commenting/discussing below.
Subject: Oracle Java Critical Vulnerability Affects Most Users
 
User Message
bettyjane RE: Oracle Java Critical Vulnerability Affects Most Users
Member 27th Apr, 2010 15:34
Score: 0
Posts: 1
User Since: 27th Jul 2009
System Score: N/A
Location: N/A
Last edited on 27th Apr, 2010 15:34
How can I remove Java Setup Error 1714 from my computer? That states "The older version of Java (TM) 6 Update 19 cannot be removed. Contact your technical support group. I cannot install jre1.6.0_17 which is necessary to repair a security breach. I tried to remove all Java from my computer, starting with updates, to no avail. Help!
Was this reply relevant?
+0
-0
M.Hansen RE: Oracle Java Critical Vulnerability Affects Most Users
Secunia Official 27th Apr, 2010 15:47
Score: 188
Posts: 376
User Since: 26th Jan 2009
System Score: N/A
Location: Copenhagen, DK
Hi

Please note that the blog is referring to the Secunia Advisory where the solution is:
Solution
Update to JRE or JDK version 6 Update 20.

Sun have a article about the Java Error 1714 you are talking about:
http://java.com/en/download/help/error_1714.xml?pr...

Good luck



MaritimeRider RE: Oracle Java Critical Vulnerability Affects Most Users
Member 1st May, 2010 09:18
Score: 22
Posts: 174
User Since: 15th Mar 2009
System Score: 100%
Location: CA
Last edited on 1st May, 2010 09:33
Whether Java or any other program, I use Revu uninstaller. Install it with a shortcut on your desktop. this is simple to use and highly effective. I have not read or heard of any negative remarks.
Although the posting states a vulnerability, Sun,ie java has the patch currently available. So no issue really.It is more an info posting and with the resolution

Also BettyJane, it is good practise to always post the specs for your computer;ie, operating system, type of computer and whether desktop or laptop.
Manufacturer, amt of hard drive space and amt. of ram also processor specs. You get the idea. All the info is available in computer properties,which you access
on your systems page.
Was this reply relevant?
+3
-0

parrotlover

RE: Oracle Java Critical Vulnerability Affects Most Users
[+]
This reply has been minimised due to a negative Relevancy Score.

-

You must be logged in to post a comment.



 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Factsheets
Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2013 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability