Mac OS X vulnerable to critical Java bug

By Matthew Broesma, ZDNet UK
Thursday, May 21, 2009 10:57 AM

Apple's Mac OS X is vulnerable to a security flaw in Java that was originally publically disclosed almost six months ago, a security researcher has warned.

The flaw affects a number of platforms running Java, and has been patched by most other operating-system vendors, noted researcher Julien Tinnes in a blog post on Tuesday.

"Unfortunately, it is still not patched in [Apple's] latest security update from just a few days ago," he wrote.

Exploits can be written purely in Java code, meaning they work on multiple platforms, Tinnes said. He recommended that Mac OS X users disable Java in their Web browsers.

"This one is a pure Java vulnerability," Tinnes wrote in the post. "This means you can write a 100 percent reliable exploit in pure Java. This exploit will work on all the platforms, all the architectures and all the browsers."

Java is enabled by default in Mac OS X browsers such as Firefox and Safari, and Tinnes said he had successfully exploited the Java bug on both browsers.

The bug (designated CVE-2008-5353 in the Common Vulnerabilities and Exposures database) was first reported to Sun in August of last year, and was patched by Sun in December.

It allows a remote attacker to take over a system, and was ranked as "highly critical" by security vendor Secunia.

The vulnerability affects multiple implementations of Java, including OpenJDK, GIJ and icedtea, as well as Sun's own implementation, security researchers said.

Tinnes noted that many companies use web applications that rely on a specific Java version, and that Java updates can break those applications. "This may be the reason why Apple's Java updates are so infrequent," he wrote.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use SCP for quick, secure file transfers

Internet Security

When you need to securely transfer a single file, SCP may be the ideal tool.


Read more »



Amendments to empower Copyright Tribunal

Blog thumbnail

As a lawyer, I often inform my clients about the need to clear licenses with the various licensing societies whenever they use works belonging to other parties. This is especially..... by Bryan Tan

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web