The InformationWeek -- Blogs
Welcome Guest. | Log In| Register | Membership Benefits

Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Apple Issues Java Security Updates For OS X 10.4, 10.5


Posted by George Hulme, Jun 15, 2009 07:31 PM

Apple released security updates today for Java for Mac OS X for Java SE 6, J2SE 5.0 and J2SE 1.4.2 on Mac OS X 10.5.7 and later. The unfortunately reality is that Sun fixed these flaws more than six months ago. Why did Apple take so long?


The good news is Apple users (who were concerned about security) can now run Software Update and get a more reasonably secured version of Java for Web browsing.

The bad news is that these flaws, including CVE-2008-5353 and a few other security problems, were fixed by Sun more than six months ago.

These flaws were serious, and could enable attackers to use especially crafted Java applets to run code of their choice on targeted system. Several weeks ago, Mac developer Landon Fuller described the flaws as "trivially exploitable" and published proof-of-concept code to prove the severity of the condition.

InformationWeek's Tom Claburn reported on this issue today:

In May, Intego, which makes security software for Macs, warned Mac users to disable Java in their Web browsers until Apple got around to fixing the Java vulnerability.

"Apple has been aware of this vulnerability for at least five months, since it was made public, but has neglected to issue a security update to protect against this issue," Intego said in a security advisory last month.

More information from Apple on today's updates is available from Apple's support site.

My question: If Sun could fix these flaws seven months ago, why did it take Apple so long to get to it?

If you'd like my mobile security and technology observations, follow me on Twitter.

« IBM CEO's Description Of Big Blue Used Against It In Court | Main | Dell's New Android Based Cell Phone? »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Microsoft Extends Visual Studio 2010 and .NET Framework 4 Beta Period
  2. Visual Basic 10 Beta 2 Also Supports Task-Based Programming
  3. Here's to the First Responders!


Join The InformationWeek Group On LinkedIn


                           


  1. Susan Boyle Beats Michael Jackson On YouTube In '09
  2. Fake Steve Jobs' 'Operation Chokehold' To Strangle AT&T?
  3. Microsoft Offers Bing iPhone App
  4. Android Round-Up: 20k Apps, Facebook Update, OS2.1 Ported
  5. Verizon Wi-Fi Program Bypasses Smartphone Users


  1. DHS Plots Its Cloud Computing Strategy
  2. Biden Kicks Off Broadband Stimulus
  3. MySQL Campaign Heats Up
  4. H1N1 Hotline Spreads Flu Info
  5. Oracle's Earnings Up 15% In 2Q
  6. Rackspace Offers FathomDB As Service

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007