On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

September 3rd, 2009

Apple plugs 15 Java for Mac security holes

Posted by Ryan Naraine @ 1:06 pm

Categories: Anti Virus, Apple, Arbitrary Code Execution, Browsers, Complex Attacks, Data theft, Denial of Service (DoS), Java, Passwords, Patch Watch

Tags: Security, Apple Macintosh, Java Applet, Apple Inc., Applet, Arbitrary Code Execution, Programming Languages, Java, Software Development, Software/Web Development

Apple today released a new version of Java for Mac to plug a total of 15 documented security vulnerabilities that could lead to remote code execution attacks via rigged Web pages.

The Java for Mac OS X 10.5 Update 5 includes patches for security holes covered by Sun Microsystems last month.

From Apple’s advisory:

  • Multiple vulnerabilities exist in Java 1.6.0_13, the most serious of which may allow an untrusted Java applet to obtain elevated privileges. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user.
  • Multiple vulnerabilities exist in Java 1.5.0_19, the most serious of which may allow an untrusted Java applet to obtain elevated privileges. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user.
  • Multiple vulnerabilities exist in Java 1.4.2_21, the most serious of which may allow an untrusted Java applet to obtain elevated privileges. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user.
  • A stack buffer overflow exists in Java Web Start command launcher. Launching a maliciously crafted Java Web Start application may lead to an unexpected application termination or arbitrary code execution.

Java for Mac OS X 10.5 Update 5 is available via the Software Update pane in System Preferences, or Apple’s Software Downloads Web site.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 25 Talkback(s)
After all...
After all, those same vulnerabilities exist
in Windows, Unix, Linux and any OS that uses
Sun's Java stack.


Nah, those same vulnerabilities existed
in Windows, Unix and... (Read the rest)
Posted by: honeymonster Posted on: 09/08/09 You are currently: a Guest | | Terms of Use
Flash, Java, libxml vulnerabilities highligh Apples systemic problem  honeymonster | 09/03/09
But none of these count  NonZealot | 09/03/09
Hateboi plenary meeting  HerbertH_02 | 09/03/09
and so what  pupkin_z | 09/03/09
It means that...  zkiwi | 09/03/09
Some questions  Lester Young | 09/04/09
A few answers  HerbertH_02 | 09/04/09
More importantly...  914four | 09/07/09
You wrote that?  xuniL_z | 09/08/09
I guess I should have been scared yesterday  DannyO_0x98 | 09/03/09
Not really the case  Richard Flude | 09/03/09
Richard Richard Richard  tonymcs@... | 09/03/09
tony, tony tony  rpmyers1 | 09/03/09
rpmeyers, rpmeyers, rpmeyers....  mgp3 | 09/04/09
!?  shis-ka-bob | 09/03/09
Well said!  914four | 09/07/09
but the number of high-risk days is zero!  shis-ka-bob | 09/03/09
Here is your evidence  honeymonster | 09/04/09
It is much worse: Tiger users a *still* vulnerable  honeymonster | 09/04/09
Nobody pays for a service pack  goff256 | 09/04/09
That's just the Apple marketing scam.  trance2tec | 09/07/09
re:That's just the Apple marketing scam  robertleeking@... | 09/07/09
Apple is turning in to a PC  Randalllind | 09/07/09
RE: Apple plugs 15 Java for Mac security holes  robertleeking@... | 09/07/09
After all...  honeymonster | 09/08/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here