<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and Privacy &#187; Java</title>
	<atom:link href="http://hijack-this.co.uk/category/java/feed/" rel="self" type="application/rss+xml" />
	<link>http://hijack-this.co.uk</link>
	<description>My ramblings on how to protect yourself online</description>
	<lastBuildDate>Thu, 01 Dec 2011 08:19:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Make sure your Java is up to date</title>
		<link>http://hijack-this.co.uk/2011/12/make-sure-your-java-is-up-to-date/</link>
		<comments>http://hijack-this.co.uk/2011/12/make-sure-your-java-is-up-to-date/#comments</comments>
		<pubDate>Thu, 01 Dec 2011 08:19:43 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security advice]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=600</guid>
		<description><![CDATA[&#160; Public Java Exploit Amps Up Threat Level — Krebs on Security: http://krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/?utm_source=feedburner&#38;utm_medium=feed&#38;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29 &#8220;An exploit for a recently disclosed Java vulnerability that was previously only available for purchase in the criminal underground has now been rolled into the open source Metasploit exploit framework. Metasploit researchers say the Java attack tool has been tested to successfully [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="mso-fareast-font-family: 'Times New Roman';"><span style="font-family: Times New Roman; font-size: small;">Public Java Exploit Amps Up Threat Level — Krebs on Security:<br />
</span><a href="http://krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">http://krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+KrebsOnSecurity+%28Krebs+on+Security%29</span></a><br />
<span style="font-family: Times New Roman; font-size: small;"><br />
&#8220;An exploit for a recently disclosed <strong>Java</strong> </span><a title="CVE-2011-3544" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3544" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">vulnerability</span></a><span style="font-family: Times New Roman; font-size: small;"> that was previously only available for purchase in the criminal underground has now been rolled into the open source </span><a href="http://metasploit.com/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">Metasploit</span></a><span style="font-family: Times New Roman; font-size: small;"> exploit framework. Metasploit researchers say the Java attack tool has been tested to successfully deliver payloads on a variety of platforms, including the latest <strong>Windows</strong>, <strong>Mac</strong> and <strong>Linux</strong> systems.&#8221;</p>
<p>&#8220;The exploit attacks </span><a title="NIST CVE Listing" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3544" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">a vulnerability</span></a><span style="font-family: Times New Roman; font-size: small;"> that exists in <em>Oracle Java SE JDK and JRE 7 and 6 Update 27</em> and earlier. If you are using <em>Java 6 Update 29</em>, or <em>Java 7 Update 1</em>, then you have </span><a title="KrebsOnSecurity: Critical Java Update Fixes 20<br />
      Flaws" href="http://hijack-this.co.uk/2011/10/critical-java-update-fixes-20-flaws/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">the latest version</span></a><span style="font-family: Times New Roman; font-size: small;"> that is patched against this and 19 other security threats. If you are using a vulnerable version of Java, it’s time to update. Not sure whether you have Java or what version you may be running? Check out </span><a title="Java Home<br />
      Page" href="http://java.com/en/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">this link</span></a><span style="font-family: Times New Roman; font-size: small;">, and then click the “Do I have Java?” link below the big red “Free Java Download” button. Apple </span><a href="http://krebsonsecurity.com/2011/11/adobe-apple-microsoft-mozilla-issue-critical-patches/" target="_blank"><span style="color: #0000ff; font-family: Times New Roman; font-size: small;">issued its own update</span></a><span style="font-size: small;"><span style="font-family: Times New Roman;"> to fix this flaw and other Java bugs earlier this month.&#8221; </span></span></span></p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F12%2Fmake-sure-your-java-is-up-to-date%2F&amp;title=Make%20sure%20your%20Java%20is%20up%20to%20date" id="wpa2a_2"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/12/make-sure-your-java-is-up-to-date/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sun Java Runtime Environment Multiple Vulnerabilities</title>
		<link>http://hijack-this.co.uk/2009/11/sun-java-runtime-environment-multiple-vulnerabilities/</link>
		<comments>http://hijack-this.co.uk/2009/11/sun-java-runtime-environment-multiple-vulnerabilities/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 11:54:06 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=210</guid>
		<description><![CDATA[Sun Java Runtime Environment Multiple Vulnerabilities Affected: JDK and JRE 6 Update 16 and earlier JDK and JRE 5.0 Update 21 and earlier SDK and JRE 1.4.2_23 and earlier SDK and JRE 1.3.1_26 and earlier Description: Sun&#8217;s implementation of the Java Runtime Environment (JRE) and Java Web Start contains multiple vulnerabilities. A specially crafted Java [...]]]></description>
			<content:encoded><![CDATA[<p>Sun Java Runtime Environment Multiple Vulnerabilities<br />
Affected:<br />
JDK and JRE 6 Update 16 and earlier<br />
JDK and JRE 5.0 Update 21 and earlier<br />
SDK and JRE 1.4.2_23 and earlier<br />
SDK and JRE 1.3.1_26 and earlier</p>
<p>Description: Sun&#8217;s implementation of the Java Runtime Environment (JRE) and Java Web Start contains multiple vulnerabilities. A specially crafted Java application, an audio or image file or an applet could trigger one of these vulnerabilities, with consequences ranging from arbitrary code execution with the privileges of the current user to denials-of-service and security restriction bypass. Note that, depending upon configuration, Java applets embedded in web pages may be opened automatically upon the loading of the page. One of the error is that the update mechanism does not update JRE to the new version when running on non-English Windows versions. There are errors in decoding DER encoded data and the parsing of HTTP headers which might lead to memory exhaustion. There is an authentication bypass vulnerability in JRE while verifying HMAC digests. Multiple buffer overflow and integer overflow vulnerabilities have been reported in JRE while processing specially crafted audio and image files. There is a command execution vulnerability in JRE which could be triggered by a specially crafted web page. There is a flaw in the implementation of security model permissions in the Java Web Start Installer. Some technical details for some of these vulnerabilities are publicly available.</p>
<p>Status: Vendor not confirmed, no updates available. [edit] Updates are available</p>
<p>References:<br />
Zero Day Initiative Advisories<br />
<a href="http://www.zerodayinitiative.com/advisories/ZDI-09-076">http://www.zerodayinitiative.com/advisories/ZDI-09-076</a><br />
<a href="http://www.zerodayinitiative.com/advisories/ZDI-09-077">http://www.zerodayinitiative.com/advisories/ZDI-09-077</a><br />
 <a href="http://www.zerodayinitiative.com/advisories/ZDI-09-078">http://www.zerodayinitiative.com/advisories/ZDI-09-078</a><br />
<a href="http://www.zerodayinitiative.com/advisories/ZDI-09-079">http://www.zerodayinitiative.com/advisories/ZDI-09-079</a><br />
<a href="http://www.zerodayinitiative.com/advisories/ZDI-09-080">http://www.zerodayinitiative.com/advisories/ZDI-09-080</a><br />
Sun Security Advisories<br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270476-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-270476-1</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270475-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-270475-1</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-269870-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-269870-1</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-269869-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-269869-1</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-269868-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-269868-1</a><br />
Product Home Page<br />
<a href="http://java.sun.com">http://java.sun.com</a><br />
SecurityFocus BID<br />
<a href="http://www.securityfocus.com/bid/36881">http://www.securityfocus.com/bid/36881</a></p>
<p>for this DO NOT rely on check for updates in JAVA control panel BUT go to <a href="http://java.com/en/download/ie_manual.jsp?locale=en&amp;host=java.com:80">http://java.com/en/download/ie_manual.jsp?locale=en&amp;host=java.com:80</a></p>
<p>if you have a 64 bit version of windows, you need to install the standard 32 bit version AND the 64 bit version <a href="http://java.com/en/download/manual.jsp">http://java.com/en/download/manual.jsp</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2009%2F11%2Fsun-java-runtime-environment-multiple-vulnerabilities%2F&amp;title=Sun%20Java%20Runtime%20Environment%20Multiple%20Vulnerabilities" id="wpa2a_4"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/sun-java-runtime-environment-multiple-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

