Skip to main content

Oracle's emergency Java patch brings sandbox bypass

posted onSeptember 3, 2012
by l33tdawg

Oracle's latest patch to close up several vulnerabilities that were being actively exploited in the wild may not have been enough, with researchers now claiming that even the latest patch (Version 7 Update 7) contains yet another vulnerability.

Researchers at Security Explorations have been scrutinising Java as part of a research project, and were able to confirm on the Bugtraq mailing list on Friday afternoon that the previous vulnerabilities discovered had been closed by the latest patch. The company also claimed that it disclosed these vulnerabilities to Oracle in April 2012. However, the latest patch (update 7) may have another vulnerability that allows an attacker to escape the Java Virtual Machine sandbox in a different manner to the previous exploit.

Source

Tags

Oracle Java Security

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th