Slashdot Mirror


Java Installer Flaw Shows Why You Should Clear Your Downloads Folder (csoonline.com)

itwbennett writes: On Friday, Oracle published a security advisory recommending that users delete all the Java installers they might have laying around on their computers and use new ones for versions 6u113, 7u97, 8u73 or later. The reason: Older versions of the Java installer were vulnerable to binary planting in the Downloads folder. 'Though considered relatively complex to exploit, this vulnerability may result, if successfully exploited, in a complete compromise of the unsuspecting user's system,' said Eric Maurice, Oracle's software security assurance director, in a blog post.

7 of 64 comments (clear)

  1. Duplicate by Nicopa · · Score: 3, Informative
    1. Re:Duplicate by simplypeachy · · Score: 4, Funny

      Naw, the other article was for a previous version of the JRE.

  2. That's why you should have a package manager by NotInHere · · Score: 5, Insightful

    nuget, apt-get, pacman, whatever. The package manager's installer code was written _once_. No need for reinventing the wheel for every damn installer in the world. No need for fixing the same bugs all over again. Just something that works, and offers updates out of the box without having to spam the user with update notices.

  3. Enough already! by b1ng0 · · Score: 4, Informative

    Get rid of this paid itwbennett schill! Two articles in one day all going to the same website. Look at his post history. Every post goes to one of two sites! If this is what whiplash meant by improving Slashdot, there is no hope left for this site.

  4. They still patch Java 6?!? by supremebob · · Score: 2

    What I learned from this post is that Oracle still does Java security patches for Java 6. I thought that it was End Of Life three years ago!

    1. Re:They still patch Java 6?!? by Billly+Gates · · Score: 2

      Sure if you buy an expensive RDMS you don't need they will fix their own products

  5. You had me... by mortonda · · Score: 5, Insightful

    at "delete all the Java installers".