Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Oracle releases security patch to fix Java vulnerabilities

Add as a preferred source on Google
Image used with permission by copyright holder

Java made headlines last week when researchers identified a security flaw in the software that allowed hackers to remotely execute malicious code in the wild. On Sunday, Oracle announced on its software security blog that it released a new security alert to repair two problems in the application. Security Alert CVE-2013-0422, which can be downloaded here, will prevent against two vulnerabilities that were remotely executable. The company’s post confirmed that the flaws were only present in Java 7 versions and did not impact Java on servers, Java desktop applications, or embedded Java.

The other change in this latest patch is that Java’s security settings will now be set to “high” by default. The more restricted setting means that a computer owner needs to directly authorize the execution of any unsigned or self-signed applets. That means a user will be notified if a malicious site attempts to run an applet and can shut down the execution before it attacks the machine. The Java Control Panel, released in update 10 of the latest Java version, can also let users turn the software on and off from their browsers.

Recommended Videos

While the patch download will secure your computer against this new attack threat, the discovery of last week’s zero-day vulnerability has led some tech experts to renew their calls to abandon Java entirely. The zero-day vulnerability is just the latest security flaw of that type to appear in the software, which is a common part of both work and home computing for many people. Users were encouraged to disable the app until the patch appeared from Oracle, but it seems unlikely that even this new security weakness will lead to a serious drop in the program’s pervasiveness.

According to InformationWeek, Oracle is slated to release another patch on Tuesday. Be prepared for lots of upkeep this week if you are a regular Java user.

Image via Roger Price

Anna Washenko
Former Contributor
Anna is a professional writer living in Chicago. She covers everything from social media to digital entertainment, from tech…
Chrome is testing an Ask Gemini button that follows your text highlights around the web
Highlight text, get Gemini. Google is making sure you never have to look for AI in Chrome again.
Google Chrome with Gemini

Google is quietly testing something in Chrome Canary that I think will either become one of the browser's most useful or its most irritating additions ever. 

It depends on how often you highlight text to copy it without wanting an AI to jump in.

Read more
Intel Core 3 test shows it could give Windows laptops a fighting chance again MacBook Neo
Fresh PassMark scores suggest Wildcat Lake is closing the gap with Apple's A18 Pro.
Intel Core Series 3 Processors Featured

Apple's MacBook Neo has shaken up the budget laptop market with its $599 price tag and surprisingly capable A18 Pro chip. But if fresh benchmark numbers are anything to go by, Intel may finally have a worthy response. The company's upcoming Core 3 304 processor has surfaced on PassMark, and the results suggest that entry-level Windows laptops could soon be much more competitive.

Intel's Core 3 304 is closing the gap with Apple's A18 Pro

Read more
Hackers leak facial recognition records tied to millions of Madison Square Garden visitors
Facial Recognition Composite

Madison Square Garden has spent years using facial recognition technology to monitor who enters its venues. Now, that same surveillance system is at the center of what could become one of the year's most troubling privacy breaches.

The cybercrime group ShinyHunters has published a massive cache of data allegedly stolen from Madison Square Garden Entertainment after the company missed a ransom deadline. According to reports, the leak includes facial recognition records, customer information, internal security assessments, and other sensitive data tied to millions of visitors. While large-scale breaches have become depressingly common, this one feels different. Most data leaks involve passwords, email addresses, or financial information. This breach reportedly includes something far more personal: information connected to how people were monitored and identified in physical spaces.

Read more