Sun patches 'critical' Java flaws

Problems with JDK, JRE and SDK

Written by Matt Chapman

Sun Microsystems has patched a number of flaws in its Java products that affect users running Windows, Linux and Solaris.

Secunia rated the flaws as 'highly critical' in a security advisory because they could allow a remote attacker to bypass security, gain system access, expose system and sensitive information and manipulate data.

Vulnerabilities were reported in the Java Developer Kit, Java Runtime Environment 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, Software Developer Kit and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier.

Problems included multiple unspecified errors that could allow hackers to use malicious applets or APIs to establish network connections on machines other than the originating host.

Other errors in Java Web Start could also be exploited to read or write local files or find the location of the Java Web Start cache.

An unspecified JRE error could also be used to move or copy arbitrary files on the system.

Sun credited Billy Rios, Dan Boneh, Collin Jackson, Adam Barth, Andrew Bortz, Weidong Shao, David Byrne and Peter Csepely with finding the vulnerabilities.

More details on the patches are available on the official Sun Security Blog.

Tags:

Further reading

Seven Microsoft security bulletins on the way

Four 'critical' patches in monthly update   More...

Warning on web 'super worm'

XSS database could cause major problems   More...

Windows 2000 flaw highlights slow Patch Tuesday

Vista and XP spared from most dangerous vulnerabilities   More...

'Greynets' waiting to snare enterprises

Consumer messaging apps leaving companies at risk   More...

Related articles

SuSE patches 'highly critical' Java flaw

Remote system access possible unless update is applied   More...

Kaspersky falls through Online Scanner flaw

Security firm unaware of 'highly critical' vulnerability   More...

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Mega Apple patch fixes iPhone, Safari, OS X bugs

Update repairs 54 vulnerabilities   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement