Apple Releases Java Update for Leopard
Apple on Thursday released an update to Java for Mac OS X Leopard. The update, number five, supersedes all previous updates and brings with it improved reliability, security, and compatibility for the cross-platform technology.
In particular, the update patches many Java-related security vulnerabilities, including some which allow untrusted Java applets to obtain elevated privileges via a Web page and potentially execute arbitrary code. There's also a patch for Java Web Start that prevents a buffer overflow from quitting an application or executing arbitrary code.
The security patches in question were released by Java-maker Sun Microsystems in early August, marking an improvement in turnaround time for Apple. In the past, the company has lagged at rolling out fixes for Java, such as this past June, when Apple finally issued an update for a bug that Sun had patched over six months prior. However, according to Computerworld, Thursday's update does not fold in Sun's most recent patch of August 11, which plugs further security holes.
