Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity
    • Development
    • Networking
    • PC Hardware

    Apple Patches Java in Mac OS X Leopard and Snow Leopard

    Written by

    Fahmida Y. Rashid
    Published March 9, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Apple patched 27 Java vulnerabilities in its latest update to close security flaws that allowed malicious Java applets to execute outside the browser.

      Apple shipped a security update that closed Java vulnerabilities in Mac OS X 10.5 (Leopard) and Mac OS X 10.6 (Snow Leopard) on March. 8. Some of the bugs could be exploited to “execute arbitrary code” outside the Java sandbox, according to Apple’s release notes. “Visiting a Web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user,” Apple wrote in the notes.

      The bugs were all part of a group of “unspecified” vulnerabilities identified in the Java run time that affected various local and networking components, according to details posted on the National Vulnerability Database. One of the security flaws allowed untrusted Java applets to create domain name resolution cache entries, which would result in DNS (Domain Name System) cache poisoning, according to an Ubuntu security advisory issued for these bugs.

      Others included not properly setting up environment variables to invoke the correct libraries, giving remote attackers user privileges when loading a badly formed class file and allowing the Swing library to bypass SecurityManager checks, the Ubuntu advisory said. These issues would have allowed malicious hackers to run external code on the computer. Another bug would have allowed a remote attacker to execute a denial of service attack, according to Ubuntu.

      Apple patched 16 vulnerabilities in Java SE 6 and 11 in Java SE 5 for the Leopard operating system, and 16 bugs in Java SE6 for Snow Leopard. The Java updates, which range between 75MB and 120MB in size, can be downloaded and installed from the Apple site or using the integrated update service on Mac OS X.

      This was Apple’s first Java update since Oct. 19, 2010, when it announced it wouldn’t include Java in future versions of Mac OS X, starting with 10.7 Lion, expected this summer. Instead of having the Java run time bundled into the operating system from the onset, OS X will go to the Oracle Website and download the latest version of the run time only if the user tries to run a Java application.

      The Mac version of Java SE 7 will be based on Oracle’s OpenJDK, and Apple will provide “most of the key components, tools and technology required for a Java SE 7 implementation on Mac OS X,” the company said.

      In the past, Apple has faced a lot of criticism for being a few months behind Oracle and other platforms with its Java updates. In fact, Oracle previously patched the same bugs in Java SE 6 as part of its 1.6.0_24 update on Feb. 15. Oracle also patched the holes in Java SE 5 with its 1.5.0_28 update.

      The lag time often exposed Mac users who remained unprotected after the vulnerabilities were publicized and other platforms had already fixed the issues, according to Dino Dai Zovi, a security consultant with Independent Security Evaluators and co-author of The Mac Hacker’s Handbook.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×