Slashdot Mirror


Polish Researcher: Oracle Knew For Months About Java Zero-Day

dutchwhizzman writes "Polish security researcher Adam Gowdiak submitted bug reports months ago for the current Java 7 zero-day exploit that's wreaking havoc all over the Internet. It seems that Oracle can't — or won't? — take such reports seriously. Is it really time to ditch Oracle's Java and go for an open source VM?"

6 of 367 comments (clear)

  1. Re:Why are people still using this? by binarylarry · · Score: 5, Insightful

    You sound like someone who shouldn't be giving technical advice.

    C/C++ has advantages over Java, just like Java has advantages over C/C++

    Saying you should use one over the other for every purpose is foolhardy.

    --
    Mod me down, my New Earth Global Warmingist friends!
  2. Ask Toolbar Really ? by Anonymous Coward · · Score: 5, Insightful

    This is the programming language that still bundles the "Ask Toolbar" crapware with their installer. Nuff said.

  3. Re:Ditch Java entirely. by characterZer0 · · Score: 5, Insightful

    Ditch Java applets entirely.

    --
    Go green: turn off your refrigerator.
  4. Re:No by X0563511 · · Score: 5, Insightful

    The real problem here is the quarterly patch cycle that seems to ignore the severity of security bugs. If you want to do a quarterly cycle that's fine - but you need to make exceptions for security bugs.

    --
    For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
  5. As a former Oracle dev by juancn · · Score: 5, Insightful
    Oracle is a huge organisation. I mean mindbogglingly huge (think planet Vogon). There is a lot of red tape that you have to cut to get anything done, and in 4 months they're probably still scheduling meetings to figure out if it should be fixed, and when, and by whom.

    Unless an SVP gets involved, it's unlikely that it will be rushed.

    1. Re:As a former Oracle dev by NettiWelho · · Score: 5, Insightful

      Perhaps they should, you know, have a department dedicated to handling these kinds of things in a timely manner then?