Apple Issues Java Security Updates For OS X 10.4, 10.5Apple Issues Java Security Updates For OS X 10.4, 10.5
Apple released security updates today for Java for Mac OS X for Java SE 6, J2SE 5.0 and J2SE 1.4.2 on Mac OS X 10.5.7 and later. The unfortunately reality is that Sun fixed these flaws more than six months ago. Why did Apple take so long?
June 15, 2009
Apple released security updates today for Java for Mac OS X for Java SE 6, J2SE 5.0 and J2SE 1.4.2 on Mac OS X 10.5.7 and later. The unfortunately reality is that Sun fixed these flaws more than six months ago. Why did Apple take so long?The good news is Apple users (who were concerned about security) can now run Software Update and get a more reasonably secured version of Java for Web browsing.
These flaws were serious, and could enable attackers to use especially crafted Java applets to run code of their choice on targeted system. Several weeks ago, Mac developer Landon Fuller described the flaws as "trivially exploitable" and published proof-of-concept code to prove the severity of the condition.
InformationWeek's Tom Claburn reported on this issue today:
"In May, Intego, which makes security software for Macs, warned Mac users to disable Java in their Web browsers until Apple got around to fixing the Java vulnerability.
"Apple has been aware of this vulnerability for at least five months, since it was made public, but has neglected to issue a security update to protect against this issue," Intego said in a security advisory last month.
More information from Apple on today's updates is available from Apple's support site.
My question: If Sun could fix these flaws seven months ago, why did it take Apple so long to get to it?
If you'd like my mobile security and technology observations, follow me on Twitter.
About the Author(s)
You May Also Like
Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and PhishingNov 01, 2023
SecOps & DevSecOps in the CloudNov 06, 2023
What's In Your Cloud?Nov 30, 2023
Everything You Need to Know About DNS AttacksNov 30, 2023
9 Traits You Need to Succeed as a Cybersecurity Leader
The Ultimate Guide to the CISSP
The Burnout Breach: How employee burnout is emerging as the next frontier in cybersecurity
Gone Phishing: How to Defend Against Persistent Phishing Attempts Targeting Your Organization
Build a Case for a Password Manager