Breaking News

Flowtica Announces Commercial Availability of Upgraded Flowtica Scribe AI Recording Pen Toshiba Demonstrates Storage Infrastructure for Scientific AI and Research at ISC 2026 DZOFILM Announces Octopus II Multi-Mount Lens Adapter & Marlin 1.4x Extender TerraMaster Prime Day 2026 Sale Offers Up to 25% Off XPG Launches INFINITY Fans and MAESTRO Air Coolers

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Researcher Finds New Bug In Java

Researcher Finds New Bug In Java

Enterprise & IT Jan 28,2013 0

Despite the recent commitment by the head of Java security that his team would fix bugs in the Java software, a researcher claims that a bug can still allow browser attacks. The Java 7 Update 10 as well as the latest Update 11 let users decide which Java applets are allowed to run within their browsers. According to Oracle, users may control the level of security that will be used when running unsigned Java apps in a web browser. Apart from being able to completely disable Java content in the browser, four security levels can be used for the configuration of unsigned Java applications:

- "Low" - Most unsigned Java apps in the browser will run without prompting
- "Medium" - Unsigned Java apps in the browser will run withoutprompting only if the Java version is considered secure.
- "High" - User will be prompted before any unsigned Java app runs in the browser.
- "Very High" - Unsigned (sandboxed) apps will not run.

But according to Adam Gowdiak, CEO of Security Explorations, none of the settings can stymie an attacker. He claims that in practice, it is possible to execute an unsigned (and malicious) Java code without a prompt corresponding to security settings configured in Java Control Panel.

Gowdiak said that a 'Proof of Concept' code that illustrates Issue 53 had been executed in the environment of latest Java SE 7 Update 11 (JRE version 1.7.0_11-b21) under Windows 7 OS and with "Very High" Java Control Panel security settings.

Gowdiak suggests that people turn to a browser with 'click-to-play,' a feature that forces users to explicitly authorize a plug-in's execution. Chrome and Firefox include support this feature.

Tags: Java
Previous Post
Pantech Introduces 5.9-inch Full-HD Smartphone
Next Post
RIM Unveils Lower BlackBerry World Price Tiers

Related Posts

  • Oracle Unveils New Services, Layouts Java's Future

  • GPU Acceleration Coming to Java

  • New Emergency Fix Releaseed For Java zero-day Exploit Released

  • New Critical Patch For Java SE Released

  • Oracle Patches Java Bugs

  • Java Said To Put Computers in High Risk

  • Google Threatens To Exclude French Web sites From Search

  • Apple Removes Java From OS X

Latest News

Flowtica Announces Commercial Availability of Upgraded Flowtica Scribe AI Recording Pen
Consumer Electronics

Flowtica Announces Commercial Availability of Upgraded Flowtica Scribe AI Recording Pen

Toshiba Demonstrates Storage Infrastructure for Scientific AI and Research at ISC 2026
Enterprise & IT

Toshiba Demonstrates Storage Infrastructure for Scientific AI and Research at ISC 2026

DZOFILM Announces Octopus II Multi-Mount Lens Adapter & Marlin 1.4x Extender
Cameras

DZOFILM Announces Octopus II Multi-Mount Lens Adapter & Marlin 1.4x Extender

TerraMaster Prime Day 2026 Sale Offers Up to 25% Off
Enterprise & IT

TerraMaster Prime Day 2026 Sale Offers Up to 25% Off

XPG Launches INFINITY Fans and MAESTRO Air Coolers
Cooling Systems

XPG Launches INFINITY Fans and MAESTRO Air Coolers

Popular Reviews

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Endorfy Thock V2 Wireless Keyboard

Endorfy Thock V2 Wireless Keyboard

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Crucial T710 2TB NVME SSD

Crucial T710 2TB NVME SSD

be quiet! Pure power 13M 750W

be quiet! Pure power 13M 750W

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed