On CHOW: Did you leave a huge tip?
BNET Business Network:
BNET
TechRepublic
ZDNet

December 14th, 2007

Finally, a 'critical' Java runtime update from Apple

Posted by Ryan Naraine @ 11:20 am

Categories: Apple, Browsers, Data theft, Exploit code, Hackers, Open source, Passwords, Patch Watch, Pen testing, Responsible disclosure, Vulnerability research, Zero-day attacks

Tags: Apple Macintosh, Apple Inc., Programming Languages, Java, Desktops, Security, Software Development, Software/Web Development, Hardware, Ryan Naraine

Finally, a ‘critical’ Java runtime update from AppleApple has shipped a long-overdue Java runtime update to plug at least 30 18 vulnerabilities that expose Mac OS X users to remote code execution attacks.

The Java Release 6 for Mac OS X 10.4 patches multiple critical holes in Java, Java 1.4 and J2SE 5.0, and includes a well-known issue that was left unpatched by Apple for more than a year.

That issue, first discovered by Google’s security team in October 2006, was the catalyst for a third-party patch by developer Landon Fuller.

[ SEE: Mac users waiting months for ‘critical’ Java runtime update ]

In all, Apple documents 30 vulnerabilities in this mega-update and warns that the most serious bug may lead to arbitrary code execution and privilege escalation.

Inexplicably, on the Mac’s software update utility, there is no mention of the security implications of this patch.  On my MacBook (see screenshot), it refers to “improved reliability and compatibility” but no explicit mention of the 30 18 high-risk flaws.

Finally, a ‘critical’ Java runtime update from Apple

This is not the first time that Apple has tried to get away with not being upfront about security fixes. Back in September, the company issued an iTunes update that made no mention whatsoever of CVE-2007-3752, a buffer overflow vulnerability that puts both Mac and Windows users at risk of arbitrary code execution attacks.

This is a significant (oversight?) because users routinely skip product updates that doesn’t contain prominent security warnings.  Apple really needs to clean up its act when it comes to upfront disclosure.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 70 Talkback(s)
Those days are ending
As Apple catches on as being the "other operating system" it is GUARANTEED to be attacked, the days of "safety" are ending as of now. Over 100 malwares now being directed at Apple, next year at this time, it will be 1000's, mark these words.... (Read the rest)
Posted by: Crestview Posted on: 12/21/07 You are currently: a Guest | | Terms of Use
Why do you hate Apple so much?  NonZealot | 12/14/07
I'm allowed  Ryan NaraineZDNet Moderator | 12/14/07
Ryan, Ryan, Ryan...  Jack-Booted EULA | 12/14/07
You must be an M$ $hill  NonZealot | 12/14/07
Love for a company???  cornpie | 12/14/07
wrong as usual  Jack-Booted EULA | 12/14/07
Then I'm only supporting you  NonZealot | 12/14/07
It's not "hatred" per se,  Jack-Booted EULA | 12/14/07
Okay, just to clarify then  NonZealot | 12/14/07
I think it's the flip flop of your message  Jack-Booted EULA | 12/14/07
Get A Life...  IT_Guy_z | 12/17/07
NZ is just looking for attention  MarcB_z | 12/14/07
So you too disagree with me?  NonZealot | 12/14/07
NZ, Axey, Lovey, et al. all pretty much the same  Jack-Booted EULA | 12/14/07
In your book  Crestview | 12/21/07
I intensely dislike LIARS and BS ARTISTS...  Feldwebel Wolfenstool | 12/15/07
It goes both ways  Qbt | 12/14/07
I'm LOL, and "That's a fact!" (NT)  Badgered | 12/14/07
That's NOT a fact!  Michael Kelly | 12/14/07
Oh and by the way...  cornpie | 12/14/07
LOL! Bury that head in the sand!  ejhonda | 12/17/07
Waaahhhhhh boo hoo sniffle  Crestview | 12/21/07
This updates was needed.  sos10@... | 12/14/07
Exactly right, I was always 100% safe with OS X!  NonZealot | 12/14/07
And you have just proven...  Qbt | 12/14/07
Proven?  ego.sum.stig@... | 12/14/07
As i said...  Qbt | 12/14/07
At least I can read  ego.sum.stig@... | 12/14/07
but at the end of the day users really just want to be safe...  doctorSpoc | 12/14/07
YEAH TOTALLY RIGHT!!!  NonZealot | 12/14/07
Gee, thanks !  Jkirk3279 | 12/15/07
Actually that is incorrect  Qbt | 12/14/07
I agree.  Jkirk3279 | 12/15/07
Stop with these wives tales already!  ye | 12/16/07
You do realise that...  ego.sum.stig@... | 12/17/07
marketshare and exploits  frgough | 12/14/07
YEAH! AWESOME FRGOUGH!! YOU ARE MY HERO!!  NonZealot | 12/14/07
It doesn't matter  Qbt | 12/14/07
Those days are ending  Crestview | 12/21/07
This should silence all the ....  ShadeTree | 12/14/07
Not Every Thing Is Said About Every Thing  DannyO_0x98 | 12/14/07
Silence?  ego.sum.stig@... | 12/14/07
YEAH!!! Way to go!!  NonZealot | 12/14/07
I have to ask...  ego.sum.stig@... | 12/14/07
What are you saying?  NonZealot | 12/14/07
I'm saying...  ego.sum.stig@... | 12/14/07
So you hate Apple!!  NonZealot | 12/14/07
You poor chap  ego.sum.stig@... | 12/14/07
But you've also expressed your hatred for Micro$ux!  NonZealot | 12/14/07
Typical!  ShadeTree | 12/14/07
Well...  ego.sum.stig@... | 12/15/07
My post was admittidly a ....  ShadeTree | 12/17/07
And yet like the proverbial...  ego.sum.stig@... | 12/17/07
Was that your impersonation ....  ShadeTree | 12/17/07
you nap?  ego.sum.stig@... | 12/17/07
Shade's an admitted "major" OEM employee  MacCanuck | 12/17/07
Considering your moniker ....  ShadeTree | 12/17/07
I make no bones  MacCanuck | 12/18/07
With the scale of marketshare  Boot_Agnostic | 12/14/07
This is not the first time...  frgough | 12/14/07
Wow!!! NonZealot!!  SquishyParts | 12/14/07
It's truly sad..  msalzberg | 12/15/07
you'll be back (NT)  Badgered | 12/17/07
LOL , NZ got you guys to swallow the hook, line and sinker!! NT  JustAnAboveAverageJoe | 12/15/07
Bashing apple yet again  otaddy | 12/15/07
Hawaii  levinson | 12/17/07
I don't think Ray is slamming Apple.  phatkat | 12/17/07
I'll change place with you in a instant.  phatkat | 12/17/07
Huh?  John Musbach | 12/19/07
RE: Huh?  John Musbach | 12/19/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads