Slashdot Mirror


Recent Apple Java Update Doesn't Fix Critical Java Flaw Claims Researcher

hypnosec writes "Just yesterday Apple released updates to fix Java vulnerabilities, but it seems the patch doesn't actually target the recently discovered high-profile Java bug that has been the talk of the web during the last two weeks. The two updates – Java for OS X 2012-005 for OS X Lion and Java for Mac OS X 10.6 Update 10 for Mountain Lion, are meant to tackle the vulnerability described in CVE-2012-0547. But according to KerbsOnSecurity, it seems Cupertino hasn't addressed the recent mega-vulnerabilities in Java as described in CVE-2012-4681." Update: 09/07 12:00 GMT by S : As readers have pointed out, these updates address flaws in Java 6, which is the version Apple maintains. The recently-reported Java vulnerabilities primarily affect Java 7, the patching of which is handled solely by Oracle. Nothing to see here.

3 of 102 comments (clear)

  1. Story is misleading. by Anonymous Coward · · Score: 5, Informative

    Except that Apple have never even installed Java 7 to be vulnerable.. this is update to their Java 6, so the story is bogus.

    It's oracles job to handle Java 7 on mac, Apple are only dealing upto 6.

  2. Mega vulnerability is for Java v7 - Apples is v6 by sasparillascott · · Score: 5, Informative

    While the Apple update doesn't fix the v7 vulnerability, it shouldn't as the Apple Java is v6 which supposedly doesn't have it (or some part of it). So this seems to make sense. To get v7 on a Mac you have to go out of your way and download v7 from Oracle separately.

  3. Stop Trolling us Slashdot by Anonymous Coward · · Score: 5, Informative

    Hey Editors, you've been trolled. The "mega-vulerabilites" described in CVE-2012-4681 don't even apply to the version of Java Apple ships. Do some homework before jumping on the bandwagon next time.