Showing posts with label oracle. Show all posts
Showing posts with label oracle. Show all posts
Friday, March 10, 2017
Java Critical Updates Apple Java 10 6 Update 15 Java 6u45 Apple Java 2013 002 Java 6u45 Oracle Java 7u21
Java Critical Updates Apple Java 10 6 Update 15 Java 6u45 Apple Java 2013 002 Java 6u45 Oracle Java 7u21
--[Updated 10:30 pm 2013-04-17 to reflect the correct version of Java provided by Apple, 6u45]
There was a scheduled Java update on Tuesday 2013-04-16. Both Apple and Oracle provided updates. Here is the list:
From Apple
1) Java for Mac OS X 10.6 Update 15
Available via Software Update. This updates Mac OS X 10.6 Snow Leopard users to Java version 6 update 45, aka 6u45.
Apples security content document:
http://support.apple.com/kb/HT5734
2) Java for OS X 2013-002
Available via Software Update. This updates OS X 10.7 Lion and 10.8 Mountain Lion users to Java version 6 update 45, aka 6u45.
Apples security content document:
http://support.apple.com/kb/HT5734
From Oracle
Java 7 update 21, aka 7u21
Available directly from Oracle via the link above.
Oracle Java SE Critical Patch Update Advisory - April 2013:
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html
PROBLEM WITH APPLES 2013-002 UPDATE
Apparently, it is NOT up-to-date!
Apple states that it is providing Java 6 update 45. However, their documentation is not listing the patching of all the known CVE security holes Oracle lists for Java 6 update 43 and below. I have documented the difference ahead.
[Note that earlier in the day it was not clear that Apple had updated beyond Java 6 update 43. Now apparently their documentation is making it clear that Java 6 update 45 is indeed what is provided. Apologies if I added to the confusion!]
Therefore, if you have OS X 10.7.3 or higher on you Mac, and you use Java while browsing the Internet, I STRONGLY suggest installing Oracles Java 7 update 21 (7u21) on top of Apples update.
Current Java CVE Issues
Oracles Java 7u21 patches 42 CVE security holes. Apples Java 6u45 patches 21 CVE security holes.
You can access Oracles Java SE Risk Matrix here:
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html#AppendixJAVA
Im going to restate Oracles list of CVEs below in order to point out what has been patched and what remains unpatched in each of the updates from Oracle and Apple. Those that are in bold have been patched by both Oracles 7u21 update and Apples 6u42 update. Those in plain text have only been updated in Oracles 7u21 update. At the end of the list is one CVE in italics that was patched by Apples 6u42 update but is not listed in Oracles 7u21 update and remains listed but unspecified in the CVE databases. Those listed in red affect Java 7 only, not Java 6.

CVE-2013-2383
CVE-2013-2384
CVE-2013-1569
CVE-2013-2434
CVE-2013-2432
CVE-2013-2420
CVE-2013-1491
CVE-2013-1558
CVE-2013-2440
CVE-2013-2435
CVE-2013-2431
CVE-2013-2425
CVE-2013-1518
CVE-2013-2414
CVE-2013-2428
CVE-2013-2427
CVE-2013-2422
CVE-2013-1537
CVE-2013-1557
CVE-2013-2421
CVE-2013-0402
CVE-2013-2426
CVE-2013-2436
CVE-2013-1488
CVE-2013-2394
CVE-2013-2430
CVE-2013-2429
CVE-2013-1563CVE-2013-2439
CVE-2013-0401
CVE-2013-2419
CVE-2013-2424
CVE-2013-1561
CVE-2013-1564
CVE-2013-2438
CVE-2013-2417
CVE-2013-2418
CVE-2013-2416
CVE-2013-2433
CVE-2013-1540
CVE-2013-2423
CVE-2013-2415
CVE-2013-2437
Summary: If I can believe both Apple and Oracles lists of patched CVEs, this means that the following CVE security holes REMAIN in Apples Java 6u45 update:
CVE-2013-1518 - Unspecified details.
CVE-2013-2439 - Unspecified details.
CVE-2013-0401
Oracle Java 7 Update 17, and possibly other versions, allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by Ben Murphy during a Pwn2Own competition at CanSecWest 2013.CVE-2013-2418 - Unspecified details.
Again note: Documentation confusion indicates these four CVEs were not patched by Apples Java 6u45 update. Ideally, Id like to verify that this is the fact in the near future. Im hoping this discrepancy in documentation is straightened out.
CONCLUSION:
If you want to surf the net with Java running, and youre using OS X 10.7.3 or higher, please install Apples Java 6u45 update FIRST, then install Oracles Java 7u21 update.
We know full well that there are still unpatched security holes in Java 7u21. Therefore, it is CRITICAL to Just Turn Java Off until you have loaded a trusted web page. Then turn Java ON and reload that page. Before you leave that page, Just Turn Java Off again. Ive covered how to turn Java on and off in previous posts.
STUPID NEWS:
Oracle has REMOVED the checkboxes for turning Java On and Off as of Java 7u21. Therefore, I cant rant about their dysfunctionality any longer, Oracle gave up trying to get their checkboxes to work, and apparently Oracle no longer even pretends there is a way to turn Java off inside its own control panel. Stupid deluxe. I have to wonder if Oracle itself understands Java well enough to get dead simple checkboxes to work.
I find this to be incredibly shameful.
Oracle: I HATE YOU.
And Apple: Either your documentation of patched CVEs is incomplete, or Oracle has provided an erroneous list of current CVEs! Either way, Id feel more secure knowing the four unpatched CVEs I list above actually had been patched by 6u45, or that they were actually inapplicable to 6u45. Im left confused as to the full state of affairs. No wonder newbies and regular users find these updates confusing.

--
Available link for download
Wednesday, November 23, 2016
Java Updates! Apple JRE 6u43 Oracle Java Plug in 7u17
Java Updates! Apple JRE 6u43 Oracle Java Plug in 7u17
--
DéDéDéjà vVvVu bZzzt@_@

I) From Apple: Java for Mac OS X 10.6 Update 14
This update includes:
- A) JRE (Java Runtime Engine) version 6u43 (1.6 update 43), installed into OS X.
- B) Java Plug-in version 6u43
About Java for Mac OS X 10.6 Update 13
Java for Mac OS X 10.6 Update 13 delivers improved security, reliability, and compatibility by updating Java SE 6 to 1.6.0_41.
On systems that have not already installed Java for Mac OS X 10.6 update 9 or later, this update will configure web browsers to not automatically run Java applets. Java applets may be re-enabled by clicking the region labeled "Inactive plug-in" on a web page. If no applets have been run for an extended period of time, the Java web plug-in will deactivate.
Please quit any web browsers and Java applications before installing this update.
About the security content of Java for OS X 2013-002 and Mac OS X v10.6 Update 14
Impact: Multiple vulnerabilities in Java 1.6.0_41
Description: Multiple vulnerabilities existed in Java 1.6.0_41, the most serious of which may allow an untrusted Java applet to execute arbitrary code outside the Java sandbox. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues were addressed by updating to Java version 1.6.0_43. Further information is available via the Java website at
http://www.oracle.com/technetwork/java/javase/releasenotes-136954.html
CVE-ID
CVE-2013-0809
CVE-2013-1493
II) From Apple: Java for OS X 2013-002, for OS X 10.7 and 10.8.
About Java for OS X 2013-002
Java for OS X 2013-001 delivers improved security, reliability, and compatibility by updating Java SE 6 to 1.6.0_41.
On systems that have not already installed Java for OS X 2012-006, this update disables the Java SE 6 applet plug-in. To use applets on a web page, click on the region labeled "Missing plug-in" to download the latest version of the Java applet plug-in from Oracle.
Please quit any web browsers and Java applications before installing this update.
About the security content of Java for OS X 2013-002 and Mac OS X v10.6 Update 14
Impact: Multiple vulnerabilities in Java 1.6.0_41
Description: Multiple vulnerabilities existed in Java 1.6.0_41, the most serious of which may allow an untrusted Java applet to execute arbitrary code outside the Java sandbox. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues were addressed by updating to Java version 1.6.0_43. Further information is available via the Java website at
http://www.oracle.com/technetwork/java/javase/releasenotes-136954.html
CVE-ID
CVE-2013-0809
CVE-2013-1493
As per usual, Apples documentation is a MESS. The security page for Java for OS X 2013-002 is inexplicably labeled as being for 2013-001. (0_o) Hopefully, when you visit the page, someone at Apple will have noticed and repaired the blundering. Again, this is a long term problem with Apples documentation team, incredibly confusing, annoying and dysfunctional. Im calling them out, yet again.
Dear Apple, please FIX YOUR DOCUMENTATION TEAM! For REALZ!
III) From Oracle: Java Plug-in 7u17, for OS X 10.7.3 - 10.8 only (not 10.6).
Java software for your computer, or the Java Runtime Environment, is also referred to as the Java Runtime, Runtime Environment, Runtime, JRE, Java Virtual Machine, Virtual Machine, Java VM, JVM, VM, or Java download.
Oracle Security Alert for CVE-2013-1493
Description
This Security Alert addresses security issues CVE-2013-1493 (US-CERT VU#688246) and another vulnerability affecting Java running in web browsers. These vulnerabilities are not applicable to Java running on servers, standalone Java desktop applications or embedded Java applications. They also do not affect Oracle server-based software.
These vulnerabilities may be remotely exploitable without authentication, i.e., they may be exploited over a network without the need for a username and password. For an exploit to be successful, an unsuspecting user running an affected release in a browser must visit a malicious web page that leverages these vulnerabilities. Successful exploits can impact the availability, integrity, and confidentiality of the users system.
Due to the severity of these vulnerabilities, and the reported exploitation of CVE-2013-1493 "in the wild," Oracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible.
Ive tested this update. The Control Panel system preferences pane is the same cruddy thing as last time. The checkboxes do NOT work. Jam the Security setting to Very High and even then, dont count on it actually working properly. Instead, if you must use Java, keep Java OFF in all your web browsers until you are at a verified safe website, then turn Java on, then reload the website for functionality. Then, BEFORE you leave that web page, turn Java OFF again.
The concept is to avoid any possibility of drive-by Java infections from maliciously hacked web pages. We learned last month that an entirely reputable iOS development website was maliciously hacked such that many developers were drive-by infected via Java. This included certain individual computers at Apple, Twitter, Facebook and others being infected. IOW, it can be extremely difficult to know if a website is absolutely safe. The best option is to Just Turn Java OFF. Only turn it on when a website REQUIRES Java to run for a service you must use. Then be sure to Just Turn Java OFF again BEFORE you leave that website. This is critical. Java is that dangerous.
Summary:
For users of OS X 10.6, only, install Java for Mac OS X 10.6 Update 14.
For users of OS X 10.7.3 through 10.8.x, install BOTH Java for OS X 2013-002 and Oracles Java Plug-in 7u17.
Be as safe as possible when surfing the Internet. Just Turn Java OFF until you require it. Just Turn Java OFF again immediately after you are finished using it.
Be seeing you, soon no doubt, for the next set of Java updates.
--
Available link for download
Subscribe to:
Posts (Atom)