Warning this article may contain opinions of the author that you and iTWire don't agree with.
Visit the last page to have your say forum.
PDFPrintE-mail

No Java fix in Mac OS X 10.5.7

Opinion and Analysis

Mac OS X 10.5.7 failed to deliver a fix for a long-standing and relatively easily exploitable vulnerability in Java.

Apple doesn't have the best reputation for delivering timely security updates. Many months can pass between the arrival of an update for an open-source program used in Mac OS X and the release of an Apple security update that incorporates it.

Even when Apple receives reports of flaws in its own software, the company isn't always quick to respond. For example, a vulnerability disclosed as part of the Month of Apple Bugs (January 2007) wasn't fixed until Security Update 2008-001 arrived in February 2008.

Although Java is a Sun project, Java for Mac OS X is maintained by Apple. This means there's no workaround for Mac users. (If a security fix is released for Apache or one of the other open-source components, affected users have the option of installing the new version without waiting for Apple.)

The first of a class of vulnerabilities in Java that allows applets in web pages to escape the Java sandbox was reported to Sun in August 2008 and fixed in December.

Its discoverer, Sami Koivu, and another security researcher, Julien Tinnes, attacked this vulnerability using an exploit written by Tinnes at this year's Pwn2Own contest. Although they succeeded in subverting Safari and Firefox, the entry was disqualified as the underlying vulnerability had already been reported.

In his blog, Tinnes explains how the vulnerability can be used to to give an applet whatever privileges the attacker wants.

How does it work? See page 2.



SPONSORED PRESS RELEASES

Independent Research Shows High Customer Satisfaction for NetSuite
NetSuite Inc. (NYSE: N), a leading vendor of cloud computing business management software suites, today announced that technology advisory firm Nucleus Research has completed an independent survey of NetSuite customers and concluded that NetSuite customers are highly satisfied, l...

Featured IT jobs

Senior Software consultant responsible for providing support on a unique enterprise level software solution for various customers, Melbourne based!
Skills Tags:   IT  ITIL  Linux  Management  RFP  Unix
This financial client has an excellent opportunity for an experienced Database Developer. SQL 2005 Some Schema design + SSIS & SSRS - 80k+super
Skills Tags:   Design  Development  SQL  SQL Server
Massive Hyperion Project requires a Hyperion Planning Architect / Lead Developer - drive home a huge Hyperion solution.
Skills Tags:   Architect  Design  Development  Hyperion
OBIEE Consultant to work on a very large greenfield OBIEE implementation to date to work end-to-end with excellent modelling & BI Server skills
Skills Tags:   Business Intelligence  Cognos  Hyperion  Informatica  Oracle  SQL

Editors Picks

Stories you may have missed 

What iTWire offers for free

E - mail News SMS Headlines Desktop Alerts News Feeds Job Alerts Technology Events Press-Releases