Forgot your password?
typodupeerror
Java Oracle Security

Latest Java Update Broken; Two New Sandbox Bypass Flaws Found 223

Posted by Soulskill
from the it-just-goes-on-and-on-my-friends dept.
msm1267 writes "Oracle's long security nightmare with Java just gets worse. A post to Full Disclosure this morning from a security researcher indicated that two new sandbox bypass vulnerabilities have been discovered and reported to Oracle, along with working exploit code. Oracle released Java 7u11 last Sunday and said it fixed a pair of vulnerabilities being exploited by all the major exploit kits. Turns out one of those two bugs wasn't completely patched. Today's bugs are apparently not related to the previous security issues."
This discussion has been archived. No new comments can be posted.

Latest Java Update Broken; Two New Sandbox Bypass Flaws Found

Comments Filter:
  • Enough Already (Score:5, Insightful)

    by Anonymous Coward on Friday January 18, 2013 @02:48PM (#42627637)

    Someone, please put Java in the browser out of our misery.

  • The same old story (Score:2, Insightful)

    by Synerg1y (2169962) on Friday January 18, 2013 @02:51PM (#42627673)
    Java's had issues with reflection before: http://stackoverflow.com/questions/3002904/what-is-the-security-risk-of-object-reflection [stackoverflow.com] .

    Considering that reflection is basically injecting code at runtime, I'd say most things in the Java world don't need it, not sure if it's on or off by default, but in 99% of scenarios I believe it should be set to off.
  • by benjfowler (239527) on Friday January 18, 2013 @03:10PM (#42627885)

    Oracle need to be called out on what appears to be an open-and-shut case of negligence.

    Only a complete idiot would take on Java and it's 600 million users without making some kind of plan for supporting it. Their approach so far has been unbelievably reckless.

    I certainly hope they don't take that attitude to Oracle Database, which is very expensive indeed, and running inside companies with lots of well paid lawyers.

  • by Anonymous Coward on Friday January 18, 2013 @03:19PM (#42627985)

    Oracle is inept at pretty much everything.

    FTFY

  • Re:Interesting (Score:5, Insightful)

    by dalias (1978986) on Friday January 18, 2013 @03:19PM (#42627987)
    Yes, in some ways I agree it is a "smear campaign", but I don't think it's an unjustified one. When a product has had vulns this serious this many times, yet maintains huge deployment due to market dominance and user lock-in, a huge smear campaign is needed to destroy it. This was the case in the past with products like BIND, Sendmail, WU-FTPD, IIS, IE, etc. and Java is just the latest necessary target.
  • by Anonymous Coward on Friday January 18, 2013 @03:24PM (#42628029)

    Sorry to say: if you haven't seen reflection used in C# you must not have been looking very hard...

  • by Bob9113 (14996) on Friday January 18, 2013 @03:28PM (#42628069) Homepage

    If Java's reflection features violate Java platform's security, it's an API design flaw, not necessarily a problem with reflection as such.

    Java is a progamming language, like C. It has access to the filesystem and can fork processes. Security is handled by the operating system, just like C. Any permission that the executing user has, the language has. That is as designed.

    The Java browser plugin, on the other hand, has a sandbox which is supposed to make it safe to run untrusted code. Turns out that trying to make it safe to run untrusted Java code is just as difficult as trying to make it safe to run untrusted C code. The security hole is in the Java sandbox, and in the notion of executing untrusted code in a language that has system access, not in the Java language.

  • by diarrhea-uh-uh (1373577) on Friday January 18, 2013 @03:46PM (#42628327)
    So sick of these headlines. Java is fine, it's the barely-used-these-days plugin that's the problem. I expect non-techy sites to omit that detail, but come on /. For those preaching that Java should be donated to Apache, give me a break. It's at the core of all "Enterprise Applications'" tech stack. Never gonna happen, nor should it. Best solution would be to decouple the plugin from the Java install and no longer shove it down people's throats.
  • by onyxruby (118189) <onyxruby@[ ]cast.net ['com' in gap]> on Friday January 18, 2013 @03:51PM (#42628377)

    I've said time and time again that Oracle doesn't get security, they just don't. They have been pulling things like this for a very long time. I never could have imagined saying this 10 years ago or so, but Oracle, you need to look at Microsoft for some pointers on handling security. Since you probably not willing to do that, I'll spell it out for you:

    When you find out about a notable security flaw you need to have a patch ready to go within 60 days.
    Meaningful notification. The everyday hacks that run IT need to have reasonable notification of security flaws.
    Workarounds. If you can't fix it, that's fine, but give me a workaround or I'm going to start uninstalling your product.
    How does it the flaw work? If you can't tell me how it works it means I have to reverse engineer it myself and this annoys me.
    The difference between theoretical flaws and something that is broken beyond saving is typically 8-10 years.
    The bad guys make a lot of money by counting on you dismissing security concerns.
    You need to make it easier to administer updates to your products.
    You need to make it easier to limit updates to your products. Why does Java 6 automatically update to 7? This is a bad, bad thing.

    From a security standpoint I can't think of anything I would wish for more than the death of Java. Every chance I have to get rid of Java I put in my two cents to do exactly that.

  • Re:Enough Already (Score:3, Insightful)

    by Anonymous Coward on Friday January 18, 2013 @04:21PM (#42628693)

    From a user-experience point of view, doing that work to enable Java to work properly for Minecraft is an abortion.

  • Re:Enough Already (Score:4, Insightful)

    by robmv (855035) on Friday January 18, 2013 @04:36PM (#42628851)

    Already done, the previous u10 added options on the Java control panel (Windows) to disable all Java feature on the browser, so if you need Java for desktop applications, you don't need expose it to the browser.

    Note: The Java plugin code was never open sourced to OpenJDK, people from IcedTea project developed a new plugin and JNLP engine for Linux. I am starting to think that Sun already knew the bad security quality of the plugin and they decided to never release that code

  • Re:Enough Already (Score:5, Insightful)

    by kbg (241421) on Friday January 18, 2013 @04:52PM (#42629041)

    This is one of the very stupid things Java has. The user has to set memory limits for the application, either using to much memory or too little, and the memory used is based on the usage for the application so that it is always a possibility to run out of memory for a Java application even if you have enough memory on your machine. This is a major usability and design flaw in Java.

To understand a program you must become both the machine and the program.

Working...