Risk

Java Vulnerability Affects 1 Billion Plug-ins

Another week, another Java vulnerability--only this one affects all versions of Java released in the past eight years.

Anyone still using a Java plug-in in their Web browser, beware: Another major, new--and as yet unpatched--vulnerability has been spotted in Java.

Unfortunately, unlike a number of the other, recently spotted Java bugs, the latest security issue affects not just the current, version 7 of Java, but also versions 5 and 6. In other words, every version of Java released for the past eight years, collectively used by approximately one billion people, is vulnerable to the exploit.

Security researcher Adam Gowdiak of Security Explorations announced the bug discovery Tuesday in a post to the Full Disclosure mailing list. "The impact of this issue is critical--we were able to successfully exploit it and achieve a complete Java security sandbox bypass in the environment of Java SE 5, 6, and 7." In other words, an attacker could use the exploit to run arbitrary code on, and remotely compromise, a vulnerable system.

Gowdiak said his firm successfully demonstrated the vulnerability on Java SE 5 Update 22, Java SE 6 Update 35, and Java SE 7 Update 7, using a fully patched 32-bit Windows 7 system, as well as five different Web browsers: Firefox 15.0.1, Google Chrome 21.0.1180.89, Internet Explorer 9.0.8112.16421 (update 9.0.10), Opera 12.02 (build 1578), and Safari 5.1.7 (7534.57.2).

"Do you have Java [plug-in] in your browser? You're vulnerable. Unless you run J2SE 1.x from the 1990s. And you shouldn't," tweeted Mikko Hypponen, chief research officer at F-Secure.

[ Learn more about Oracle software vulnerabilities. See Oracle Database Passwords Easily Cracked. ]

Given the critical nature of the flaw, is it safe to use Java? "Taking into account that now the issue affects Java SE 5, 6, and 7, we advise users of Java SE software to disable Java plug-ins in their Web browsers and wait for the patches from Oracle," said Gowdiak via email.

When might the relevant vulnerability be patched by Oracle? The company's next regularly scheduled, quarterly patch release is due October 16, 2012, meaning there might not be enough lead time for the company to properly code and test a fix. On the upside, however, Gowdiak said he's seen no evidence that the bug, which his company reported privately to Oracle--has been spotted by anyone else, or that it's being used in in-the-wild attacks.

If Gowdiak's name sounds familiar, it's because by the end of August, his firm had discovered 30 security issues involving Java, including a recently disclosed Java 7 security sandbox bypass that Oracle has yet to patch. But the bugs spotted earlier this year could only be used to bypass the Java 7 sandbox.

According to the Security Explorations tracking page for vendors that have been notified of vulnerabilities, Oracle Tuesday confirmed the new vulnerability, and said "the issue will be addressed in a future Java SE Critical Patch Update." As of Monday, meanwhile, Oracle told Security Explorations that 18 outstanding bugs identified by the company had been fixed "in the main codeline," and are queued up for release in a forthcoming critical patch update. Two other Java bugs, meanwhile, are still under investigation.

Security Explorations earlier this month also notified IBM of 17 Java-related security issues in its products, 10 of which "successfully demonstrate a complete IBM J9 Java VM security sandbox bypass," said Gowdiak. The security issues are present in the IBM software development kit (SDK), which is a Java Standard Edition implementation from IBM that's available for a number of platforms, including AIX, Linux, z/OS, as well as for the Eclipse and WebSphere platforms.

Security Explorations said it verified the IBM SDK Java Technology Edition vulnerabilities in version 7.0 SR1 as well as version 6.0 SR11, both for Linux 32-bit x86 systems. It said that the Java vulnerabilities it found in the IBM SDK are unique to IBM's software, and don't duplicate flaws reported to Oracle. IBM Thursday told Security Explorations that "relevant development teams are working to address the weaknesses." IBM hopes to release the "fixed SDK software" in November 2012.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Valentine's Emails Laced with Gandcrab Ransomware
Kelly Sheridan, Staff Editor, Dark Reading,  2/14/2019
High Stress Levels Impacting CISOs Physically, Mentally
Jai Vijayan, Freelance writer,  2/14/2019
Mozilla, Internet Society and Others Pressure Retailers to Demand Secure IoT Products
Curtis Franklin Jr., Senior Editor at Dark Reading,  2/14/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5780
PUBLISHED: 2019-02-19
Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events.
CVE-2019-5781
PUBLISHED: 2019-02-19
Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
CVE-2019-5782
PUBLISHED: 2019-02-19
Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
CVE-2019-5783
PUBLISHED: 2019-02-19
Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform a Dangling Markup Injection attack via a crafted HTML page.
CVE-2019-5766
PUBLISHED: 2019-02-19
Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.