Secunia CSI7
Advisories
Research
Forums
Create Profile
Our Commitment
PSI
PSI API
CSI
OSI
xSI
Vulnerabilities
Programs
Open Discussions
My Threads
Create Thread
Statistics
About

Forum Thread: Java JRE 1.7.0.0

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
PSI

This thread has been marked as resolved.
bjm__ Java JRE 1.7.0.0
Member 4th Aug, 2011 17:52
Ranking: 64
Posts: 374
User Since: 9th Mar, 2009
System Score: 100%
Location: US
Good day Community
Just a brief query re Jave JRE 1.6.x SA 45173
filehippo change log for JRE 1.7.0.0 reports Updates to Security
I seldom if never run Java...so, IDK
Has anyone updated/installed JRE 1.7.0.0 even though PSI does not prompt 1.7 as patch/fix for 1.6.x
Does PSI continue to report same 1.6.x venerability with 1.7.0.0

Thanks

Post "RE: Java JRE 1.7.0.0" has been selected as an answer.
Anthony Wells RE: Java JRE 1.7.0.0
Expert Contributor 4th Aug, 2011 21:06
Score: 2445
Posts: 3,332
User Since: 19th Dec 2007
System Score: N/A
Location: N/A

Hello bjm ,

As far as I can understand , version 7 is a major platform change to replace version 6 ; it is supposedly fairly much compatible with stuff made by/using 6 , but is not yet being pushed out by Oracle/Sun in a big way as a replacement per se for simple home users (such as I).

6 U26 is still offered by Sun sites if you go to get the latest Java download :-

http://www.java.com/en/

Whether any of the current 6 U26 security vulnerabilities are applicable/patched is not currently specified - as far as I can find .

If you only use Java occasionally , you could try the version 7 download (easy to find at filehippo) for yourself (check the "comments" tab if you go there , ref OOo) :-

http://www.filehippo.com/download_jre_32/

Was thinking of doing so myself , but haven't got round to it as yet ; maybe next week !! ??

Would be interested to hear what anyone else thinks/knows .

Take care

Anthony

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+3
-0
Maurice Joyce RE: Java JRE 1.7.0.0
Handling Contributor 4th Aug, 2011 22:56
Score: 11743
Posts: 9,000
User Since: 4th Jan 2009
System Score: N/A
Location: UK
@bjm
Just done a trial for U by installing the 32 Bit version on my PC.

It shows as fully patched in the Scan Results & Secure Browsing Sections as version 7.0.0.147.

Hope there are no more questions as I have uninstalled it as I do not keep any JAVA programmes permanently installed on my main platform!



--
Maurice

Windows 7 SP1 64 Bit OS
HP Intel Pentium i7
IE 11 for Windows 7 SP1
16GB RAM
Was this reply relevant?
+3
-0
bjm__ RE: Java JRE 1.7.0.0
Member 5th Aug, 2011 00:13
Score: 64
Posts: 374
User Since: 9th Mar 2009
System Score: 100%
Location: US
Last edited on 5th Aug, 2011 00:22
Interesting << It shows as fully patched in the Scan Results & Secure Browsing Sections as version 7.0.0.147 >>
Curious... PSI is not prompting 1.7 as fix for SA 45173
(over my pay grade)
I was either going to pull 1.7 from filehippo or just uninstall Java.
Only time I ever use JRE is for showing OSI to friends
& I always have all Java browser plugins disabled.
Just noticed I typed venerabilty for vulnerability.
Egg on my face ;-D

Thanks ~~~~

Was this reply relevant?
+1
-1
Maurice Joyce RE: Java JRE 1.7.0.0
Handling Contributor 5th Aug, 2011 00:35
Score: 11743
Posts: 9,000
User Since: 4th Jan 2009
System Score: N/A
Location: UK
Filehippo has a history of pulling updates that have "not got the seal of approval" -the JAVA site has not offered it yet which, I suspect, will be the time for Secunia to think about "official changes".

If U rarely use JAVA join the club & dump it!

--
Maurice

Windows 7 SP1 64 Bit OS
HP Intel Pentium i7
IE 11 for Windows 7 SP1
16GB RAM
Was this reply relevant?
+2
-1
Jersey_Devil RE: Java JRE 1.7.0.0
Member 5th Aug, 2011 06:11
Score: 9
Posts: 26
User Since: 29th Apr 2010
System Score: N/A
Location: US
Java JDK/JRE version 7 available @ Oracle.com here: http://www.oracle.com/technetwork/java/javase/down...

A quick glance thru the release notes does not indicate that this patches the version 6 update 26 (build 1.6.0_26-b03) vulnerability. http://secunia.com/advisories/45173

--
Gateway NV59C
Win 7 HP SP1 x64, XP Home SP3
FFox latest Ex-PLODE-r 11
PSI v2 MVPS Hosts
Avast 9 FREE
Was this reply relevant?
+0
-0
Anthony Wells RE: Java JRE 1.7.0.0
Expert Contributor 5th Aug, 2011 13:58
Score: 2445
Posts: 3,332
User Since: 19th Dec 2007
System Score: N/A
Location: N/A

Hello bjm ,

Are you still using Open Office ?? It seems there is a bug with JRE version 7 loading in OOo and LibO and people who need it have gone back to version 6 .

Take care

Anthony

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+3
-0

This thread has been marked as locked.


 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2014 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability