Site icon The Mac Security Blog

Oracle Kills 40 Java Bugs in One Fell Swoop

Oracle has released Java SE 7u25 with fixes for a colossal 40 security vulnerabilities. Most of the bugs fixed in Java SE 7u25 are “remotely exploitable without authentication,” according to Oracle’s security team.

This critical patch applies to Java 7 Update 21 and all versions before, Java 6 Update 45 and before, and Java 5.0 Update 45 and before. Apple’s Java for OS X 2013-004 and Mac OS X v10.6 Update 16 was released for Mac OS X v10.6.8, OS X Lion v10.7 or later, and OS X Mountain Lion v.10.8 or later.

Oracle noted the following details of the vulnerabilities fixed in this update:

In addition to the above notables, Oracle’s Eric Maurice mentioned that one of the fixes affects the Javadoc tool and the documents it creates, describing the issue and resolution as follows:

Some HTML pages that were created by any 1.5 or later versions of the Javadoc tool are vulnerable to frame injection.  This means that this vulnerability (CVE-2013-1571, also known as CERT/CC VU#225657) can only be exploited through Javadoc-generated HTML files hosted on a web server.  If exploited, this vulnerability can result in granting a malicious attacker the ability to inject frames into a vulnerable web page, thus allowing the attacker to direct unsuspecting users to malicious web pages through their web browsers.  This vulnerability has received a CVSS Base Score of 4.3.  With the release of this Critical Patch Update, Oracle has fixed the Javadoc tool so that it doesn’t produce vulnerable pages anymore, and additionally produced a utility, the “Java API Documentation Updater Tool,” to fix previously produced (and vulnerable) HTML files.

Below is the full list of CVEs resolved in this critical patch update:

Oracle strongly recommends that all Java SE 7 users upgrade to this release. Mac users can go to Oracle’s website to download Java SE 7u15 as advised. Users running OS X Lion v10.7 or later and OS X Mountain Lion v10.8 or later can head over to Apple’s Java for OS X 2013-004 download page to install the 64.01 MB update to 1.6.0_51. Mac OS X v10.6.8 Snow Leopard users can go to Apple’s Java for Mac OS X 10.6 Update 15 download page to install the 69.39 MB update to 1.6.0_45. Users running Java SE with a browser can download the latest release from Java.com.

Share this: