Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 16th, 2012, 05:57 PM
ronjor's Avatar
ronjor ronjor is online now
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,202
Default Oracle Java SE Critical Patch Update Advisory - October 2012

Quote:
Description

A Critical Patch Update is a collection of patches for multiple security vulnerabilities. The Critical Patch Update for Java SE also includes non-security fixes. Critical Patch Updates are cumulative and each advisory describes only the security fixes added since the previous Critical Patch Update and Security Alert. Thus, prior Critical Patch Update and Security Alert advisories should be reviewed for information regarding earlier accumulated security fixes. Please refer to:
http://www.oracle.com/technetwork/to...2-1515924.html
  #2  
Old October 16th, 2012, 08:16 PM
Mman79 Mman79 is offline
Very Frequent Poster
 
Join Date: Sep 2012
Location: North America
Posts: 1,678
Default Re: Oracle Java SE Critical Patch Update Advisory - October 2012

It's about time. I wish I could place bets on how quickly the patch is found to have yet another exploitable hole in it. Thanks.

Edit: I don't recall them ever sending out a patch for the very last vulnerability that was found a few weeks ago.
  #3  
Old October 16th, 2012, 11:09 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,612
Default Re: Oracle Java SE Critical Patch Update Advisory - October 2012

Thanks Ron!

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.147 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #4  
Old October 17th, 2012, 04:57 AM
PJC PJC is offline
Very Frequent Poster
 
Join Date: Feb 2010
Location: Internet
Posts: 2,962
Default Oracle Java SE Critical Patch Update Advisory - October 2012

Here, we go again...

BTW, thanks, Ron!
  #5  
Old October 17th, 2012, 11:25 AM
Ocky's Avatar
Ocky Ocky is offline
Very Frequent Poster
 
Join Date: May 2006
Location: George, S.Africa
Posts: 2,537
Default Re: Oracle Java SE Critical Patch Update Advisory - October 2012

Still not secure !

Quote:
However, talking to The H's associates at heise Security, Gowdiak said that a critical security hole that allows attackers to break out of the Java sandbox continues to exist in Java. According to the researcher, Oracle told him that the October CPU was already in its final testing phase when he reported the vulnerability. Therefore, this vulnerability and another, less critical hole will be closed at the next scheduled Java patch day on 19 February 2013.

http://www.h-online.com/security/new...e-1731176.html
__________________
Ubuntu Kubuntu Xubuntu Scientific Linux
  #6  
Old October 17th, 2012, 12:10 PM
Mman79 Mman79 is offline
Very Frequent Poster
 
Join Date: Sep 2012
Location: North America
Posts: 1,678
Default Re: Oracle Java SE Critical Patch Update Advisory - October 2012

February...February? The smiley icons I have available to choose from here in the post can't properly reproduce the look I have on my face right now. Java security issues are making IE 6 look like Chrome.
  #7  
Old October 17th, 2012, 06:34 PM
BoerenkoolMetWorst BoerenkoolMetWorst is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: Outer space
Posts: 2,053
Default Re: Oracle Java SE Critical Patch Update Advisory - October 2012

Quote:
According to the researcher, Oracle told him that the October CPU was already in its final testing phase when he reported the vulnerability. Therefore, this vulnerability and another, less critical hole will be closed at the next scheduled Java patch day on 19 February 2013.
Instead of coming to the conclusion that because the patch was already in final testing phase the vulnerability will be fixed the next patch day 4 months later they could come to the conclusion that perhaps they should make patch day monthly and create an out-of-band patch so that the hundred millions users around the world they so gladly advertise are not left vulnerable for so long..

Quote:
Originally Posted by Mman79
It's about time. I wish I could place bets on how quickly the patch is found to have yet another exploitable hole in it. Thanks.
Lol, not necessary when there still exploitable holes left unpatched.
  #8  
Old October 19th, 2012, 01:01 AM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,134
Post Re: Oracle Java SE Critical Patch Update Advisory - October 2012

See also: http://threatpost.com/en_us/blogs/or...-update-101712
Quote:
Oracle will not patch a critical sandbox escape vulnerability in Java SE versions 5, 6 and 7 until its February Critical Patch Update, according to the researcher who discovered the flaw. Adam Gowdiak of Polish security firm Security Explorations told Threatpost via email that Oracle said it was deep into testing of another Java patch for the October CPU released yesterday and that it was too late to include the sandbox fix.

Gowdiak's team did share a technical description of the issue and source and binary codes of proof-of-concept exploit code.
  #9  
Old October 20th, 2012, 06:09 PM
BrandiCandi
 
Posts: n/a
Default Re: Oracle Java SE Critical Patch Update Advisory - October 2012

Quote:
Originally Posted by Mman79
February...February? The smiley icons I have available to choose from here in the post can't properly reproduce the look I have on my face right now. Java security issues are making IE 6 look like Chrome.
EXACTLY. There's no obscene smiley icon that properly expresses the deep feelings I harbor against Java.
  #10  
Old October 20th, 2012, 08:25 PM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: Oracle Java SE Critical Patch Update Advisory - October 2012

I can wait until it gets to the point that no one touches oracle Java with a barge pole and it finally Dies off,there will be No tear tears from me.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:25 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums