• On BNET: 3 worst things about the iPhone 3G S

November 29, 2005 12:25 PM PST

Sun plugs serious holes in Java

  • 5 comments
Related Stories

Java flaws open door to hackers

June 14, 2005

Sun looks to sweeten Java

March 15, 2005
Sun Microsystems has fixed five security bugs in Java that expose computers running Windows, Linux and Solaris to hacker attack.

The flaws are "highly critical," according to an advisory from Secunia posted Tuesday. Vulnerabilities that get that ranking--one notch below "extremely critical," the security monitoring company's most severe rating--typically open the door to a remote intruder and to full compromise of the system.

All the flaws affect the Java Runtime Environment, or JRE, in computers loaded with Microsoft Windows, Linux or Sun's own Solaris operating system. This is the software many computer owners have on their system to run Java applications. The bugs could allow an intruder to use a Java application to inappropriately read and write files, or to run code on a victim's computer, Sun said in three separate security advisories released late Monday.

The vulnerabilities also affect specific versions of the Sun Java Software Development Kit (SDK) and Java Development Kit (JDK), according to those advisories.

The French Security Incident Response Team, or FrSIRT, rated the issues "critical" in an alert posted Tuesday.

There have been no reported cases of the flaws being exploited by hackers, Sun said in a statement.

Three of the bugs lie in application programming interface, or API, parts of the Java Runtime Environment. Another vulnerability lies in the Java Management Extensions implementation in the software. The fifth flaw is in an unspecified part of the JRE.

Sun, based in Santa Clara, Calif., is urging people to install updated software to protect their systems. It has released updates to address the issues, including JDK and JRE 5.0 Update 4, which was actually delivered on June 23. A newer version, Update 5, was issued in September, but Sun would not say if additional security problems were fixed in that release. The software can be downloaded from the Sun Java Web site.

See more CNET content tagged:
JRE, Sun Microsystems Inc., Java, Java development, Sun Solaris

Add a Comment (Log in or register) (5 Comments)
  • prev
  • 1
  • next
No reported incidents?
by n3td3v November 29, 2005 12:49 PM PST
How good is Sun's intelligence infrastructure for detecting hacker actvitiy? Do they have Honey's or are they hoping for information to be brought forward from security intelligence and research centers. Whats Sun's point of contact if users have information to provide? How big a hack do they call no reported hackers exploiting? Do they mean corporations getting hax0red or are they saying, no single home user has been compromised? The mind boggles. I'm sure if I poke around at http://www.sun.com/software/security/ i'll get some answers.
Reply to this comment
A few answers, perhaps?
by December 6, 2005 3:57 AM PST
> "How good is Sun's intelligence infrastructure for detecting hacker actvitiy? Do they have Honey's or are they hoping for information to be brought forward from security intelligence and research centers."

If you understood what Java is, and particularly the nature of the bugs to which this report corresponds, you understand how it isn't possible to set up honey pots to trap these types of algorithm based issues.

As anybody can license and implement their own Java implementation, it is up to each JRE/JDK vendor to ensure the security of their products, subject to the battery of tests and checks specified as part of the license.

While it would be folly to assume any software is perfectly secure, Java's security model has been checked by many experts, as anyone can review the code - indeed I suspect this is how these particular problems were found. This model has thus far resulted in very very few security alerts. (Actually, can anyone think of a comparible technology which has as few or fewer security alerts as Java?)


> "Whats Sun's point of contact if users have information to provide?"

For a programming bug like this I'd be tempted to (also?) check out their bug/issue reporting site. This is likely to bring the issue to the maximum number of eyeballs in the shortest time.


> "How big a hack do they call no reported hackers exploiting? Do they mean corporations getting hax0red or are they saying, no single home user has been compromised?"

Presumably it means that no software is circulating which is known to use these exploits. The problem was fixed long before anyone exploited it.
Bug in JAVA ???
by FutureGuy November 29, 2005 2:37 PM PST
I thought Java can't have bugs, only software from MS can contain bugs right??? ;) Well I have yet to hear a serious security bug like this is .Net.
Reply to this comment
You're kidding right?
by Bill Dautrive November 30, 2005 1:41 PM PST
.net is more of a security mess then Java ever could be.

Java is not perfect, but like most software companies not named Microsoft, they are generally fixed quickly and without ever being exploited.
Write once........
by SqlserverCode November 30, 2005 6:57 AM PST
Write once, infect everywhere

http://otherthingsnow.blogspot.com
Reply to this comment
(5 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Sun Microsystems (-0.54%) -0.05 9.15
Dow Jones Industrials (-0.72%) -59.02 8,124.15
S&P 500 (-0.59%) -5.17 877.51
NASDAQ (-0.02%) -0.32 1,752.23
CNET TECH (-0.06%) -0.78 1,258.87
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right