Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

Java Vulnerability Affects 1 Billion Plug-ins

Another week, another Java vulnerability--only this one affects all versions of Java released in the past eight years.

Anyone still using a Java plug-in in their Web browser, beware: Another major, new--and as yet unpatched--vulnerability has been spotted in Java.

Unfortunately, unlike a number of the other, recently spotted Java bugs, the latest security issue affects not just the current, version 7 of Java, but also versions 5 and 6. In other words, every version of Java released for the past eight years, collectively used by approximately one billion people, is vulnerable to the exploit.

Security researcher Adam Gowdiak of Security Explorations announced the bug discovery Tuesday in a post to the Full Disclosure mailing list. "The impact of this issue is critical--we were able to successfully exploit it and achieve a complete Java security sandbox bypass in the environment of Java SE 5, 6, and 7." In other words, an attacker could use the exploit to run arbitrary code on, and remotely compromise, a vulnerable system.

Gowdiak said his firm successfully demonstrated the vulnerability on Java SE 5 Update 22, Java SE 6 Update 35, and Java SE 7 Update 7, using a fully patched 32-bit Windows 7 system, as well as five different Web browsers: Firefox 15.0.1, Google Chrome 21.0.1180.89, Internet Explorer 9.0.8112.16421 (update 9.0.10), Opera 12.02 (build 1578), and Safari 5.1.7 (7534.57.2).

"Do you have Java [plug-in] in your browser? You're vulnerable. Unless you run J2SE 1.x from the 1990s. And you shouldn't," tweeted Mikko Hypponen, chief research officer at F-Secure.

[ Learn more about Oracle software vulnerabilities. See Oracle Database Passwords Easily Cracked. ]

Given the critical nature of the flaw, is it safe to use Java? "Taking into account that now the issue affects Java SE 5, 6, and 7, we advise users of Java SE software to disable Java plug-ins in their Web browsers and wait for the patches from Oracle," said Gowdiak via email.

When might the relevant vulnerability be patched by Oracle? The company's next regularly scheduled, quarterly patch release is due October 16, 2012, meaning there might not be enough lead time for the company to properly code and test a fix. On the upside, however, Gowdiak said he's seen no evidence that the bug, which his company reported privately to Oracle--has been spotted by anyone else, or that it's being used in in-the-wild attacks.

If Gowdiak's name sounds familiar, it's because by the end of August, his firm had discovered 30 security issues involving Java, including a recently disclosed Java 7 security sandbox bypass that Oracle has yet to patch. But the bugs spotted earlier this year could only be used to bypass the Java 7 sandbox.

According to the Security Explorations tracking page for vendors that have been notified of vulnerabilities, Oracle Tuesday confirmed the new vulnerability, and said "the issue will be addressed in a future Java SE Critical Patch Update." As of Monday, meanwhile, Oracle told Security Explorations that 18 outstanding bugs identified by the company had been fixed "in the main codeline," and are queued up for release in a forthcoming critical patch update. Two other Java bugs, meanwhile, are still under investigation.

Security Explorations earlier this month also notified IBM of 17 Java-related security issues in its products, 10 of which "successfully demonstrate a complete IBM J9 Java VM security sandbox bypass," said Gowdiak. The security issues are present in the IBM software development kit (SDK), which is a Java Standard Edition implementation from IBM that's available for a number of platforms, including AIX, Linux, z/OS, as well as for the Eclipse and WebSphere platforms.

Security Explorations said it verified the IBM SDK Java Technology Edition vulnerabilities in version 7.0 SR1 as well as version 6.0 SR11, both for Linux 32-bit x86 systems. It said that the Java vulnerabilities it found in the IBM SDK are unique to IBM's software, and don't duplicate flaws reported to Oracle. IBM Thursday told Security Explorations that "relevant development teams are working to address the weaknesses." IBM hopes to release the "fixed SDK software" in November 2012.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
7 Truths About BEC Scams
Ericka Chickowski, Contributing Writer,  6/13/2019
DNS Firewalls Could Prevent Billions in Losses to Cybercrime
Curtis Franklin Jr., Senior Editor at Dark Reading,  6/13/2019
10 Notable Security Acquisitions of 2019 (So Far)
Kelly Sheridan, Staff Editor, Dark Reading,  6/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-12865
PUBLISHED: 2019-06-17
In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.
CVE-2017-10720
PUBLISHED: 2019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi name. This application is installed o...
CVE-2017-10721
PUBLISHED: 2019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet functionality enabled by default. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and settings, car ga...
CVE-2017-10722
PUBLISHED: 2019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi password. This application is install...
CVE-2017-10723
PUBLISHED: 2019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that an attacker connected to the device Wi-Fi SSID can exploit a memory corruption issue and execute remote code on the device. This device acts as an Endoscope camera that allows it...