Oracle patches dangerous Java holes

Oracle on Monday was distributing a patch for Java software flaws deemed so dangerous that the US Department of Homeland Security said that people should stop using it.

By:AFP
| Updated on: Jan 15 2013, 18:45 IST

Oracle on Monday was distributing a patch for Java software flaws deemed so dangerous that the US Department of Homeland Security said that people should stop using it.


'Oracle recommends that this Security Alert be applied as soon as possible because these issues may be exploited 'in the wild' and some exploits are available in various hacking tools,' Oracle's Eric Maurice said in a blog post.

You may be interested in

MobilesTablets Laptops
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
Vivo X100 Pro 5G
  • Asteroid Black
  • 16 GB RAM
  • 512 GB Storage
10% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage

The patch was crafted to fix two holes that hackers could slip through in Java 7 software used by web browsers to interact with websites.

Also read
Looking for a smartphone? To check mobile finder click here.

'To be successfully exploited, an attacker needs to trick an unsuspecting user into browsing a malicious website,' Maurice said.

'The execution of the malicious applet within the browser of the unsuspecting users then allows the attacker to execute arbitrary code in the vulnerable system.'

Essentially, hackers could take advantage of the vulnerability to infect and take control of computers by getting them to visit a booby-trapped website.

Oracle raised Java security settings so that mini-programs referred to as 'applets' will need to get permission from website visitors before being able to run on people's computers, according to Maurice.

Despite the patch, which was released by Oracle on Sunday, computer specialists at the Department of Homeland Security advised people to avoid using the software 'unless it is absolutely necessary,' even after updating.

'This will help mitigate other Java vulnerabilities that may be discovered in the future,' the DHS Computer Emergency Readiness Team said Monday in an updated advisory on its website.

Java is distributed by business software powerhouse Oracle and is popular because it lets developers create websites in code that can be accessed regardless of a computer's operating system.

Java was created by Sun Microsystems, which was purchased by Northern California-based Oracle.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on Whatsapp channel,Twitter, Facebook, Google News, and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 15 Jan, 18:43 IST
NEXT ARTICLE BEGINS