Oracle Confirms Java 7 Vulnerability, Promises Fix 'Will Be Available Shortly'

By Alexandra Burlacu email: a.burlacu@mobilenapps.com | Jan 13, 2013 02:17 PM EST

Share This Story

  • Print
  • Email

Oracle has confirmed the zero-day vulnerability found in Java 7 that grabbed the spotlight last week, and promised to fix the issue soon.

Oracle's promise to fix things comes after the U.S. Department of Homeland Security advised PC users to disable Java in  Web browsers, as hackers are exploiting a security flaw to attack PCs.

Follow us

"A fix will be available shortly," Oracle told Reuters in a statement late Friday, Jan. 11. The company did not offer further details regarding when the update will become available.

The security threat in Java 7 made headlines on Thursday, Jan. 10, after the U.S. Computer Emergency Readiness Team (US-CERT), which pertains to the National Cyber Security Division of the Department of Homeland Security, issued an alarming vulnerability note:

"Overview - Java 7 Update 10 and earlier contain an unspecified vulnerability that can allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.

Description - Java 7 Update 10 and earlier contain an unspecified remote-code-execution vulnerability. This vulnerability is being attacked in the wild, and is reported to be incorporated into exploit kits.

Impact - By convincing a user to visit a specially crafted HTML document, a remote attacker may be able to execute arbitrary code on a vulnerable system."

Through this critical security hole, attackers can execute malicious software on a victim's system. Cybercriminals quickly exploited the security hole in the wild, and made it available in common exploit kits. The same day, Apple took steps to block Java 7 on OS X 10.6 and later to protect Mac users.

The next day, Security Explorations, the security firm that identified most of the recent Java vulnerabilities, said the zero-day code only worked because Oracle had not properly addressed an old vulnerability. Security Explorations notified Oracle back in August 2012 that it has an insecure implementation of the Reflection API. Oracle issued a patch in October 2012, but it was not a complete fix.  

Mozilla decided on Friday to add all recent versions of Java to its Firefox add-on blocklist, blocking Java 7 Update 9, Java 7 Update 10, Java 6 Update 37, and Java 6 Update 38. Firefox had already blocklisted other Java versions over other vulnerabilities.

Users will be able to use the plug-in again once Oracle releases Java 7 Update 11, which aims to address the security issue. In the meantime, users should uninstall or at least disable Java in their machine, regardless of what browser or operating system they are using.

Get the Most Popular Mobile&Apps Stories in a Weekly Newsletter

© 2013 Mobile & Apps All rights reserved. Do not reproduce without permission.

Join Our Conversation

Smartphones
ZTE Grand SZTE Grand S Release Date In U.S. Put On Hold Until 2014
Nokia Yet Again Sues HTC Over Patent Infringement
Nexus 4 Rocking Android 4.3 Version Stars In New Photos, Video
HTC Desire 600 Now Official: Quad-Core Mid-Range Smartphone With Beats Audio, BlinkFeed
Tablet / Laptop / PC
Discounted Prices For Refurbished iPad 4Apple Drops Prices On Refurbished iPad Mini, iPad 4 Tablets
Hisense Introduces Sero 7 Tablets With $99 Starting Price To Challenge Nexus 7
Sony Xperia Tablet Z Gets Dunked In A Fishtank, Survives
Samsung Galaxy Tab 3 7.0 Stars In New Video
Gadgets
Google GlassGoogle Glass Is Creepy, Says Early Glass User
Xbox One And PlayStation 4: On The Matter Of Shared And Used Games
Recharge Your Phone In 20 Seconds With This Revolutionary Device
Ouya Will Be At E3 2013, But Not Where You Think
OS / Software
Android 4.3 Jelly BeanNexus 4 Rocking Android 4.3 Version Stars In New Photos, Video
Former Nokia Team Jolla, Announces First Sailfish Powered Smartphone For Asia
Android 4.2.2 Jelly Bean Update For Samsung Galaxy S3 Transform It Into Galaxy S4 (To Some Extent)
iOS 7 To Come With Flickr, Vimeo Integration
Internet / Social Media
FaceTimeAT&T Promises Cellular Video Calls, Mobile Video Chat For All Customers
Flickr Boasts 'Spectacular' Redesign, Offers A Whopping 1TB Of FREE Storage
Download 40 GB In A Second: Researchers Set Up World's Fastest Wi-Fi Network In Germany
YouTube Shoppable Videos - Will Google Hit A New Jackpot?
What's App
NBA Jam Windows PhoneTiger Woods 12 and NBA Jam Are The Latest EA Sports Games To Come Exclusive To Nokia Lumia
Microsoft YouTube App For Windows Phone Still Up And Running Despite Google Takedown Notice
Pandora Updates Web And Mobile Apps With Easier Facebook Sharing
Nokia Launched LiveSight For HERE Maps On Windows Phone 8

DON'T MISS

Galaxy Tab 3
Samsung Galaxy Tab 3 7.0 Stars In New Video
Samsung announced its new Galaxy Tab 3 7.0 Android Jelly Bean tablet at the end of April, but a new
Huawei Ascend Mate
Nokia And Huawei Working On 6-Inch Phablets, Claim Report
Phablets have become popular due to the Samsung Galaxy Note line of devices, so it is no surprise
Nokia Carl Zeiss Optics
Nokia To Unleash Lumia EOS Smartphone With 41-Megapixel Camera In July
The world's best camera phone is almost here, as the Nokia Lumia 'EOS' will reportedly launch in
Hisense Sero 7 Pro and Sero 7 LT Tablets
Hisense Introduces Sero 7 Tablets With $99 Starting Price To Challenge Nexus 7
Hisense unveiled its new Sero 7 tablets that will likely give the Nexus 7 a run for its money with
Microsoft YouTube App Windows Phone 8
Microsoft YouTube App For Windows Phone Still Up And Running Despite Google Takedown Notice
Breathe a sigh of relief, Windows Phone 8 fanboys, as the YouTube app is still alive and kicking.
Xperia Tablet Z
Sony Xperia Tablet Z Gets Dunked In A Fishtank, Survives
A Sony Xperia Tablet Z user decided to test the tablet's waterproof capabilities by placing it in a

Samsung Galaxy S4 In New Color Options
Samsung Galaxy S4 Sells 10M Units In First Month, More Color Options Coming This Summer
The new Samsung Galaxy S4 flagship smartphone sells faster than any of its predecessors, reaching
Sprint 4G LTE
More BlackBerry Devices On The Way, Says Sprint
If you were left impressed with the major releases from BlackBerry earlier this year viz. BlackBerry
Galaxy S3 Jelly Bean Update
Android 4.2.2 Jelly Bean Update For Samsung Galaxy S3 Transform It Into Galaxy S4 (To Some Extent)
The Android 4.2.2 Jelly Bean firmware for the Samsung Galaxy S3 has been leaked and many users of
LG Optimus GJ
LG Optimus GJ Waterproof Smartphone Now Official, Will Sport $600 Price Tag
LG has just unveiled the Optimus GJ smartphone, its first high-end waterproof handset. Optimus GJ
Copyright © 2013 Mobile & Apps All rights reserved. mobilenapps
Real Time Analytics