New Java Exploits Brewing

Attackers have released exploit code targeting two previously patched flaws in Sun Microsystems' Java Runtime Environment (JRE) and Java Software Development Kit (SDK).

The flaws could allow an attacker to remotely execute code on a Windows, Linux or Solaris system. Sun issued patches for both vulnerabilities in December.

The JRE component allows JavaScript code to be executed on most operating systems, including Windows, Mac OS, Linux and Unix.

The vulnerabilities affect JRE 1.3.x, 1.4.x and 1.5.x, as well as versions 1.3.x and 1.4.x of the SDK and versions 1.5.x of the Java Development Kit.

Danish security vendor Secunia rates one of the vulnerabilities as 'highly critical', the company's second-highest level, owing to the possibility for remote code execution.

Eric Sites, vice president of research and development at Sunbelt Software, told vnunet.com that, although exploits against Java vulnerabilities are uncommon, they do still pop up.

Article

Further to Humptys post, I`ve just been informed that Java 5 update 10 is ready for download.

Have to be honest, and say that I`m not 100% sure about this.

Complete enlightenment would be appreciated. Do I need it, and could it be a security risk ?

Win XP Sp2. Firefox2 browser. Adobe Flash Player 9 plugin.

Thanks

Errr, Java 6 came out a couple of months ago :P

EDIT: Having said that, just checked Java.com and they're offering version 5 update 10 as the latest. You can get version 6 from the Sun Microsystems site HERE. (Had it here since its release and no problems to report)

Errr, Java 6 came out a couple of months ago :P

EDIT: Having said that, just checked Java.com and they're offering version 5 update 10 as the latest. You can get version 6 from the Sun Microsystems site HERE. (Had it here since its release and no problems to report)

Thanks JDPower.

I`ll try that, but I`m wondering if Java Platform carries out similar function to ActiveX.

What would I miss if I disabled Java Scripts and Java in FireFox ?

Suppose I could always try, and find out first hand.

Regards

I don't have Java installed.

Almost no websites use Java.

And I have JavaScript disabled through the NoScript extension for Firefox, and only has JavaScript enabled for a handful of sites.

I don't have Java installed.

Almost no websites use Java.

And I have JavaScript disabled through the NoScript extension for Firefox, and only has JavaScript enabled for a handful of sites.

Thanks Eldmannen,

Just unticked the two boxes in FF options>content.

Well there`s a thing. Deselect Java Script: Reload the page: All menu icons gone from above this reply window. :o

Reselect Java Script: Reload page: Your all ahead of me. Menu icons back. :)

There`s a use for Java Script, although not an essential one. Will keep Java itself deselected.

It`s nice to know that you can select and deselect Java Script without having to relaunch FF.

Regards

Edit: Spelling

And I have JavaScript disabled through the NoScript extension for Firefox, and only has JavaScript enabled for a handful of sites.

I agree with this, I think this is the way to go. I know that some people find this extension , initially, a bit of a nuisance. But, when you get used to it, it gives you a genuine feeling of being in control. It's my second favourite extension, after Adblock.

I don't have Java installed.

Almost no websites use Java.

And I have JavaScript disabled through the NoScript extension for Firefox, and only has JavaScript enabled for a handful of sites.

Ditto. ;)

And adblockplus.