Apple Finally Patches Java Vulnerability
macs4all writes "Apple has finally addressed the Java vulnerability that nearly everyone else patched months ago. Available now for OS X 10.4 and 10.5, and through Apple's Software Update service, this update patches a flaw in the Java Virtual Machine that could potentially allow a malicious Java applet to execute arbitrary code on the machine. Apple had previously advised users to turn off Java temporarily in their Web browsers."
It is truly sad that Apple still just don't "Get" security. Makes me a sad panda to think it is going to take some sort of devastating worm or virus for them to finally wake up and smell the shit they are pumping out.
*we know what's best for you
In other news, a major car manufacturer finally did a recall on a faulty transmission found in their economy class sedan. This defect caused the car to explode if driven in third gear or higher. The manufacturer previous advised users to just keep their vehicles under 30mph (48 kph) and everything would be fine.
Also, an oven manufacturer recently found a defect in the temperature management system for the oven. The manufacturer advised to keep the oven under 200 degrees to prevent a cascading failure.
It's a shame that Apple doesn't consider software defects to be a potentially life threatening condition. Someone successfully stealing your identity could be just in the same ballpark as a major car malfunction or an exploding stove.
...and this means that we can expect Vic20_love to come along any moment now and complain that his OS X 10.1 machine from 19-dickity-6 doesn't have a patch out yet, so Apple sucks.
Not that Apple doesn't suck, but you don't really need to troll for reasons.
(Bye, karma, nice knowing you...)
--saint
Just wondering. PPC Java for OSX is even more out of date than x86 Java.
The latest java on PPC is 1.5, and I'm sure it's out of date too...
Had this been a post about Microsoft instead of Apple, I'd imagine there'd be a lot of "ha ha micro$0ft sucks" posts now.
Rich also chided Apple for leaving such a major hole unpatched for so long.
Yeah, Apple, a meager market share (not accounting for cost per unit of course) isn't an excuse to leave stuff like this busted. I hereby CHIDE you!
Well, maybe.
First off, pretty much every time we get one of these "OMG!" stories on slashdot about a security flaw going unfixed, we find out that it's not nearly as bad as suggested by the slashdot summary. In this case, the description linked to from the slashdot article says: "The Java plug-in does not block applets from launching file:// URLs. Visiting a website containing a maliciously crafted Java applet may allow a remote attacker to launch local files, which may lead to arbitrary code execution." So that's quite a bit less scary than the slashdot summary makes it sound. If I'm understanding correctly, it apparently doesn't let the attacker launch any code the attacker choses. It only lets the attacker launch code that's already present on the user's filesystem. And doesn't the java sandbox model prevent java applets from writing to the filesystem? So the attacker really may have very little opportunity to execute arbitrary code of the attacker's choosing.
Second: the slashdot summary says, "Apple had previously advised users to turn off Java temporarily in their Web browsers." Wow, that sounds really awful. It makes it sound like a really serious problem. But wait, the apple page doesn't say this. According to the tidbits.com article, Rich Mogull is the one who says the fix is to disable applets. The link to Rich Mogull's advice is a link within tidbits.com.
Find free books.
Even after updating, I've found that's advice I can live with.
Holy crap that's a huge update. How big is the original install? Sorry for the people on dial-up.
I do not understand...but since when have problems in Java been Apple's problems?
Seriously, the title talks of problems with Java and then goes ahead to mention that these problems are Apple's problems - absurd!
May be the title should be changed to say something like: -
"...Java exploits a vulnerability on Apple's OSX..."
Apple Guy "Halt who goes there"
Black Haxor "It is I the black haxor, I seek the finest computer coders to join me in my quest"
Apple Guy " You shall not pass"
Black Haxor "What ?"
Apple Guy "Non shall pass"
Black Haxor "I have no quarrel with you, good sir, but I must move on"
Apple Guy "Then you shall first install photoshop and make an offering at the alter of Steve and promise to buy hardware at twice the price from the lords of apple".
Black Haxor "I command you to stand aside! for I am the Black Haxor"
Apple Guy "I move for no man for I am impervious to all your tricks for I run OSX"
Black Haxor "So be it"
[Black Haxor pulls out his laptop and starts to type]
[HAH]
Apple Guy "What have you done ?"
Black Haxor "I have exploited a java script bug on your system and signed you up as the local leader for the "Pedo's Rights" association and then passed the details on to the the local parents and teachers group"
Apple Guy "what is this trickery, for such is impossible, you lie"
[a rabble of middle aged parents turn up]
Crowd "THERE HE IS, GET HIM!!"
Apple Guy "BAH! Tis but a lie"
Black Haxor "run man, they weld clubs and carry petrol containers and mean harm upon you"
Apple Guy "They do not wish me harm as my laptop colour matches my shoes, thus they come to tell me how great my karma is"
[15 minutes later the Black Haxor is staring at a smoldering pile on the ground]
Black Haxor "Sigh"
[Crosses bridge]
Apple does not like Java. It's a competing development platform like Flash. If they did not have to ship it they wouldn't. You'll notice how long it takes them to update Java, that's why.
The update fails to install on some machines, mine included.
Use your favourite search engine (Bing me no Bings) to find references to:
Rich And Stupid is not so bad as Working For Rich And Stupid.
I mean hell us Mac users can FINALLY get back on the internet. Shooo took long enough We just sat here living in fear. Mac powered off. Checking in with our Windows friends to see when it was safe again, while flashbacks to the "Code Red" nightmare from year ago filled our head. Oh wait, Code Red is when my company swore off ever using Windows for critical systems.... Scratch that.
But anyways us Mac fan bois are back! WOO HOO!!!! "finally"
Get a PC. :D
is so very much simpler.
Game! - Where the stick is mightier than the sword!
I think apple should launch another ad campaign with the "Cool" mac guy on one side and a security guy on the other! The "Cool" guy could put his head in the sand and shout "Don't make me do stuff!".
Is it really too much to ask for Java 1.6 for all the poor bastards still stuck with PowerPC machines that need Classic, so can't migrate to 10.5?
We have three Macbooks in my office room, the java update did not install on any of them. The error messages are not very discriptive either...
This makes even happier that my mac greeted me with "The Java update for 10.5 could not be installed" this morning.
...these aren't my real teeth.
But seriously, I've just turned off Java on all my browsers and systems. Why even bother with it on? Does *anybody* even use applets anymore? I don't run into pages with applets at least. Can't turn your head without running into javascript, and the foul and horrid flash is quite common (flick2flash is my personal lord and savior!), but applets? I think there are two stories in here. Apple still needs to hire someone to champion security (i.e. technologies *and* updates) and all browsers should disalble java as default as it is just a bunch of dead weight.
...but I didn't have a mac, so I had to use a vm with an unpatched linux (ubuntu 8.10 actually). I tried to convince a guy with a mac in the audience to go to my exploit url, but he was not willing... One cool thing of this exploit is that it is pure java, so the same exploit can work on linux, mac and windows.
Here is a writeup on the vulnerability: http://blog.cr0.org/2009/05/write-once-own-everyone.html
And here is a proof-of-concept exploit: http://landonf.bikemonkey.org/code/macosx/CVE-2008-5353.20090519.html
You can decompile it to see what's going on exactly.
Enjoy.
I've had this patch for quite a long while, actually. It's been available as a Developer Preview from ADC for a month or so already. (requires free registration to download)
No excuse for Apple for not rolling it out to the masses sooner, though.
I would also add that in 1998 the automatic patching and updates concept was brand new, and even the windows update site wasn't pushing patches, but rather desktop themes and other nonsense "add ons".
Apple has a really good updating service built into OSX, so good that I barely notice that it has done anything when it is finished. There aren't as many patches as I get bombarded with on Windows, but I still don't think that means "they are in 1998".
I'm a 2000 man.
problems with librxtxSerial.jnilib arrrgh!
they can do something about this "The update "Java for Mac OS X 10.5 Update 4" can't be installed error message I get when I try to install the thing.
But, I wanted socialized health insurance!
Anybody else notice the rabid, hostile tendencies of the typical Mac Fanboy's postings? A little disturbing...
[Insert pithy line of moxie here.]
I had the same issue with one of my macs and had to do the same :)
Strange bug.
Mexico: 100% conservative's America now!