Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

brooklynite

(94,303 posts)
Sun Jan 13, 2013, 10:57 AM Jan 2013

Oracle Corp to fix Java security flaw "shortly"

Source: Chicago Tribune

BOSTON (Reuters) - Oracle Corp said it is preparing an update to address a flaw in its widely used Java software after the U.S. Department of Homeland Security urged computer users to disable the program in web browsers because criminal hackers are exploiting a security bug to attack PCs.

"A fix will be available shortly," the company said in a statement released late on Friday.

Company officials could not be reached on Saturday to say how quickly the update would be available for the hundreds of millions of PCs that have Java installed.

The Department of Homeland Security and computer security experts said on Thursday that hackers figured out how to exploit the bug in a version of Java used with Internet browsers to install malicious software on PCs. That has enabled them to commit crimes from identity theft to making an infected computer part of an ad-hoc computer network that can be used to attack websites.


Read more: http://articles.chicagotribune.com/2013-01-12/business/sns-rt-us-usa-java-securitybre90b0ex-20130112_1_java-software-java-browser-plug-ins-computer-security-experts



It's going to be interesting to eventually find out where the real risk was coming from, to warrant a Government warning.
23 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Oracle Corp to fix Java security flaw "shortly" (Original Post) brooklynite Jan 2013 OP
I'll laugh if its related in any shape or form to Stuxnet dipsydoodle Jan 2013 #1
"Shortly" Yeah, right. hobbit709 Jan 2013 #2
LOW-tech here: I learned in Googling that I had Java 6 & should not have been running UTUSN Jan 2013 #3
Java and JavaScript are different animals getting old in mke Jan 2013 #5
Any thoughts on whether I should install 7 now or wait for the fix? UTUSN Jan 2013 #6
In my professional opinion, Gore1FL Jan 2013 #10
O.K., thanks (so far)!1 So what is my "need for it" & how will I know it?!1 UTUSN Jan 2013 #11
It'll prompt you that you need it. n/t Gore1FL Jan 2013 #14
Java is a heck of a lot safer than the Microsoft dot-net and silverslime crap. Bernardo de La Paz Jan 2013 #12
Today it definitely isn't high density Jan 2013 #13
They will never have safe versions either Gore1FL Jan 2013 #15
I am so ignorant when it comes to computers... Sekhmets Daughter Jan 2013 #4
I'll let someone else with knowledge answer you for sure, but in my experience AllyCat Jan 2013 #7
This is my second Mac... Sekhmets Daughter Jan 2013 #17
This is my first Mac, though I have worked on several in various jobs. RebelOne Jan 2013 #19
Java is not used by your computer... brooklynite Jan 2013 #8
Hey Thanks! Sekhmets Daughter Jan 2013 #16
Same here. davidwparker Jan 2013 #22
I have a new computer...Apple no longer installs Java... Sekhmets Daughter Jan 2013 #23
I just removed the Java program. AllyCat Jan 2013 #21
I hope so. Many sites I use google news, bing news, etc rely on java for some of the results Purveyor Jan 2013 #9
UPDATE - Java update expected on Tuesday brooklynite Jan 2013 #18
I got a pop up when I went to NYT's puzzle page today that cbayer Jan 2013 #20

UTUSN

(70,641 posts)
3. LOW-tech here: I learned in Googling that I had Java 6 & should not have been running
Sun Jan 13, 2013, 11:11 AM
Jan 2013

anything previous to Java 7, which is the affected program. See below for a DUer's recommendations for uninstalling Java 6, which I have now done (64 bit). I did NOT see any JavaSCRIPT that we are told NOT to disable/uninstall for use in DU.

So far, I haven't seen any differences: Am able to REC DU threads, haven't tried YouTubes yet, don't know whether I can respond to DU jury yet.

QUESTION: With the Java fix coming, now that I have UNinstalled Java 6, should I install 7 NOW and disable it pending the fix? Or wait and do it together with the fix?

Here's from the Computer group:

**************QUOTE**********

from DUer/Earth Bound Misfit's thread in the Computer group:

http://www.democraticunderground.com/10954629

The Security tab > Untick enable Java content is a new feature in Ver 7 update 10...not available in previous versions.

Below is what I believe is the easiest way to disable ALL Java plugins on Windows computers (credit Grinler site Owner/Admin @ Bleepingcomputer)
http://www.bleepingcomputer.com/forums/topic481462.html/page__view__findpost__p__2945754

Using a version of Java that is not Version 7 Update 10

1. Uninstall all versions of Java.
2. Download and install Version 7 Update 10 from the following locations depending on the bit-type of Windows:

Windows Offline (32-bit) http://javadl.sun.com/webapps/download/AutoDL?BundleId=71835
Windows Offline (64-bit) http://javadl.sun.com/webapps/download/AutoDL?BundleId=71837

3. Disable Java in your browsers by following these steps: http://www.java.com/en/download/help/disable_browser.xml

Java will now be disabled in your browsers. You must do this step for all users on Windows computers.


Currently using Version 7 Update 10

1. Disable Java in your browsers by following these steps: http://www.java.com/en/download/help/disable_browser.xml. Java will now be disabled in your browsers. You must do this step for all users on the Windows computer.


********UNQUOTE**********

getting old in mke

(813 posts)
5. Java and JavaScript are different animals
Sun Jan 13, 2013, 11:20 AM
Jan 2013

so disabling Java in the browser won't affect sites that rely on JavaScript.

UTUSN

(70,641 posts)
6. Any thoughts on whether I should install 7 now or wait for the fix?
Sun Jan 13, 2013, 11:30 AM
Jan 2013

Please be very literal and specific with any steps, like, if installing 7 do I DISable it immediately until the fix is available? Thanks.

Gore1FL

(21,095 posts)
10. In my professional opinion,
Sun Jan 13, 2013, 12:23 PM
Jan 2013

You should wait until you have a need for it before installing.

Java is going to have future vulnerabilities as well. Ultimately, there is no safe version.

UTUSN

(70,641 posts)
11. O.K., thanks (so far)!1 So what is my "need for it" & how will I know it?!1
Sun Jan 13, 2013, 12:47 PM
Jan 2013

I learned from the DU threads that Java and JavaSCRIPT are different, that DU uses JavaSCRIPT, and after UNinstalling Java I have been able to use all DU features I use (Rec; jury) and have played YouTube (with stalling, as always) -- so what does Java do for me?!1 I'm serious/sincere in asking, so thanks for any answers!1

Sekhmets Daughter

(7,515 posts)
4. I am so ignorant when it comes to computers...
Sun Jan 13, 2013, 11:11 AM
Jan 2013

I use an iMac and haven't a clue what this Java thing is...do I need to worry?

AllyCat

(16,135 posts)
7. I'll let someone else with knowledge answer you for sure, but in my experience
Sun Jan 13, 2013, 11:42 AM
Jan 2013

Macs and Apples never seem to be affected by this garbage. Husband and I are thinking about getting one when our Windows PC finally kicks it.

Sekhmets Daughter

(7,515 posts)
17. This is my second Mac...
Sun Jan 13, 2013, 02:05 PM
Jan 2013

bought the first in 2004...then Apple changed to the Intel chips in 2005 and eventually I could no longer download the newest browsers. I began having minor problems in 2011 and by the autumn of 2012 it was a real pain in the neck so I bought a new one. I must admit to loving my Macs...For computer dummies like myself it is a 'no brains required' system. Of course, less than 3 months after I bought my new one, Apple updated their iMacs...raised the base price $100. but included things that previously were $500. worth of upgrades. This is now the second time I've been off in my timing with Apple.

RebelOne

(30,947 posts)
19. This is my first Mac, though I have worked on several in various jobs.
Sun Jan 13, 2013, 04:25 PM
Jan 2013

My company updated all the computers to Mac Minis, and I love them so much that when my PC died, I bought a Mac Mini. I love it, and from now on, I will only buy Macs. Theirs is definitely a no-brains system.

brooklynite

(94,303 posts)
8. Java is not used by your computer...
Sun Jan 13, 2013, 11:46 AM
Jan 2013

...it's used by your web browser (Safari, Firefox, Chrome) for some website features (for example, YouTube videos). Go into the Preferences section of each to disable the functions.

Safari: Preferences: Security

Chrome: Preferences: Settings: Advanced Settings: Privacy: Content Settings

Firefox: Preferences: Content

Sekhmets Daughter

(7,515 posts)
16. Hey Thanks!
Sun Jan 13, 2013, 01:58 PM
Jan 2013

I have a new Mac OS X 10.8.2 and I would have to download Java (this I found out today when I realized I should probably Google the issue myself) Whatever I have instead of Java, I have no problems watching YouTube videos...so I guess I'll just pass up the whole Java thing.

davidwparker

(5,397 posts)
22. Same here.
Mon Jan 14, 2013, 02:31 AM
Jan 2013

I just checked my Java version and it is not 7.

Typing "java -version" at a command prompt shows you what you have. Since we have the same OS X release and if you've not updated Java either, it is probably the same as mine: 1.6 (or 6).

Sekhmets Daughter

(7,515 posts)
23. I have a new computer...Apple no longer installs Java...
Mon Jan 14, 2013, 08:44 AM
Jan 2013

If you want it you must go to the Oracle site and download it. I haven't missed it so I don't think I will bother.

AllyCat

(16,135 posts)
21. I just removed the Java program.
Mon Jan 14, 2013, 12:21 AM
Jan 2013

Is that good enough? YouTube still runs. Some other stuff doesn't. I will check out what you have said to make sure it is working the way I expected by removing it though. Thanks!

 

Purveyor

(29,876 posts)
9. I hope so. Many sites I use google news, bing news, etc rely on java for some of the results
Sun Jan 13, 2013, 12:19 PM
Jan 2013

options.

brooklynite

(94,303 posts)
18. UPDATE - Java update expected on Tuesday
Sun Jan 13, 2013, 03:51 PM
Jan 2013
PC World:

Oracle is working on an update to address a flaw in its Java software.

The company says it will release a patch that will fix 86 vulnerabilities in Java 7 on Tuesday.

The Department of Homeland Security last week said computer users should disable the program in web browsers because hackers were using a zero-day vulnerability to attack computer systems. Criminals were using the flaw to stealthily install malware on the computers of users who visit compromised websites.

cbayer

(146,218 posts)
20. I got a pop up when I went to NYT's puzzle page today that
Sun Jan 13, 2013, 04:34 PM
Jan 2013

said my Java was out of date, that a needed security update was available and that my java had been disabled.

Looked fishy to me, so I skipped it.

Latest Discussions»Latest Breaking News»Oracle Corp to fix Java s...