On GameFAQs: The top 10 forgotten RPGs
BNET Business Network:
BNET
TechRepublic
ZDNet

August 23rd, 2007

Mac users waiting months for 'critical' Java runtime update

Posted by Ryan Naraine @ 9:38 am

Categories: Apple, Botnets, Browsers, Data theft, Exploit code, Firefox, Hackers, Metasploit, Microsoft, Open source, Passwords, Patch Watch, Pen testing, Responsible disclosure, Spam and Phishing, Spyware and Adware, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Security, Apple Macintosh, JDK, Java, Sun Microsystems Inc., Apple Inc., Apple Mac OS X, Ryan Naraine

Where’s that Mac OS X Java update?

Ten months ago (October 2006), a member of Google’s security team discovered and reported two code execution vulnerabilities in Sun’s Java ICC (image) profile parsing code.

Seven months later (May 2007), Sun issued an update (JDK 1.5.0_11-b03) that was available for Window, Solaris, and Linux.

One big problem. It’s August 2007 and Apple’s Java runtime has not yet been updated, meaning that millions of Mac OS X users are at risk of remote code execution attacks.

An alert from IBM’s ISS X-Force spells out the danger:

Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03, and 1.6.x before 1.6.0_01-b06, allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) via a crafted JPEG or BMP file.

Chris Evans, the Google engineer credited with finding/reporting this issue, told me he only dealt with Sun’s security response team during the disclosure process.

“I reported the issue just to Sun. My personal understanding is that Sun itself coordinates the heads-up with all affected consumers. You might want to contact Sun directly to see if they included Apple,” Evans said in an e-mail exhange.

Apple’s security team does not answer questions on specific patches (my queries routinely get a non-response about taking security seriously) so it’s anyone’s guess when a Mac OS X update will ship.

[ SEE: Mac Developer mulling OS X equivalent of ZERT ]

Tired of waiting for Apple, developer Landon Fuller has taken matters into his own hands, creating a third-party patch with full source code.

Fuller, a former engineer in Apple’s BSD Technology Group and one of the primary faces behind the “Month of Apple Fixes” project earlier this year, released a proof-of-concept exploit alongside the patch to show how a rigged image file can be used to crash a fully patched browser.

“It may be difficult to exploit, but it’s a fairly long time to be sitting on a public issue,” Fuller said in an instant messaging exchange. “Admittedly it’s time consuming to push out a new Java release, especially if you need to merge in local JRE/JDK changes and run the full TCK validation suite, but it shouldn’t take this long,” he added.

Fuller’s patch requires the use of Unsanity’s Application Enhancer. Alternatively, Mac OS X users can disable Java in your browser to close the most likely vector.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 56 Talkback(s)
Got a mouse in your pocket?
Who's we? Are you talking to yourself, or are you so smug as to believe you speak for the mac community as a whole?... (Read the rest)
Posted by: rtk Posted on: 08/24/07 You are currently: a Guest | | Terms of Use
Not a problem at all  frgough | 08/23/07
Really?  Ryan NaraineZDNet Moderator | 08/23/07
May have you confused  frgough | 08/23/07
Not so.  ShadeTree | 08/23/07
Even so...  yyuko@... | 08/23/07
agreed  Badgered | 08/23/07
Makes me wonder why people trust MS and Bill Gates.  nomorems | 08/23/07
Makes me glad I don't use OSX!  NonZealot | 08/23/07
the exploits are only for windoze  Linux Geek | 08/23/07
Linux Geek this exploit is for mac not windows (NT)  SO.CAL Guy | 08/23/07
still osx is safe, see...  Linux Geek | 08/23/07
Windows must be safe too if exploits are only for Windoze.  ye | 08/23/07
Just like Bill Gates is also known as William Gates...  nomorems | 08/23/07
Only by immature people.  ye | 08/24/07
Do me a favor?  yyuko@... | 08/23/07
In case you are unaware...  nomorems | 08/23/07
you can't call yourself a zdnet talkback reader...  rtk | 08/24/07
Makes me glad you don't use OSX!  nomorems | 08/23/07
Still waiting for a patch for ActiveX for 10 years  Resuna | 08/24/07
Specifically which vulnerability are you referring to?  ye | 08/24/07
Isnt Sun responsible for this...  Stuka | 08/23/07
No  toadlife | 08/23/07
To make it clearer...  yyuko@... | 08/23/07
Maybe because it is their platform that is ....  ShadeTree | 08/23/07
Windows and Linux were also...  Stuka | 08/23/07
Even so...  yyuko@... | 08/23/07
Nice Dodge  ShadeTree | 08/23/07
Apple controls hardware and software  NonZealot | 08/23/07
Define "fails miserably" in context please  MarcB_z | 08/23/07
Fails Miserably  yyuko@... | 08/23/07
Does not meet the criteria  MarcB_z | 08/23/07
Criteria?  rtk | 08/24/07
What?????  MacGeek2121 | 08/24/07
and how's that related to the main story?  royalstream | 08/24/07
it's sun's responsability  Linux Geek | 08/23/07
Geek of nothing...  yyuko@... | 08/23/07
Because  BroGnorik | 08/23/07
Java 6 update 2 was made available to Apple...  LilBambi_z | 08/24/07
We'll be just fine...  mgregory98 | 08/23/07
Got a mouse in your pocket?  rtk | 08/24/07
Where's the Java?  YinToYourYang-22527499 | 08/23/07
Erm...  zkiwi | 08/23/07
I hate to break it to you. Dice is an IT career site.  nomorems | 08/23/07
And yet...  zkiwi | 08/23/07
Soooo...where are all these exploits Ryan?  CowLauncher | 08/23/07
Mac user here too  Ryan NaraineZDNet Moderator | 08/23/07
Fair enough Ryan, but...  CowLauncher | 08/23/07
Do you know for sure?  Ryan NaraineZDNet Moderator | 08/23/07
Sorry. While I am a Mac user, I have never logged into MySpace.  nomorems | 08/23/07
Derek  dwerk | 08/24/07
Soooo...wait for people to exploit before fixing??  dwerk | 08/24/07
No excuses  Richard Flude | 08/23/07
Yeah, yeah. Like everyone says until Mac is 30% I won't worry.  nomorems | 08/23/07
Agreed.  Resuna | 08/24/07
Ask Sun  SquishyParts | 08/23/07
I've been waiting for this patch.....really!?!  Laff | 08/24/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline