US-CERT Alert TA13-107A: Oracle has released multiple updates - April 17, 2013!

vpnavy

Super Moderator
Staff member
Jun 15, 2008
35,160
18,660
York County, PA (USA)
Primary Interest:
All Treasure Hunting
National Cyber Awareness System
April 17, 2013
Oracle has released multiple updates for Java SE
java_03.gif

toilet_newspaper.gif
Systems Affected - JDK and JRE 7 Update 17 and earlier, JDK and JRE 6 Update 43 and earlier, JDK and JRE 5.0 Update 41 and earlier and JavaFX 2.2.7 and earlier

Overview - Oracle has released a Critical Patch Update (CPU) for Java SE. Oracle strongly recommends that customers apply CPU fixes as soon as possible.

Description - Oracle Java SE Critical Patch Update Advisory - April 2013 describes the update as:

A Critical Patch Update is a collection of patches for multiple security vulnerabilities. The Critical Patch Update for Java SE also includes
non-security fixes. Critical Patch Updates are cumulative and each advisory describes only the security fixes added since the previous
Critical Patch Update and Security Alert. Thus, prior Critical Patch Update and Security Alert advisories should be reviewed for information
regarding earlier accumulated security fixes.

Impact - A remote, unauthenticated attacker could execute arbitrary code, cause a denial of service, or gain unauthorized access to your files or system.

Solution - Apply Updates - Oracle Java SE Critical Patch Update Advisory - April 2013 includes the
following information:

Developers can download the latest release from Java SE Downloads.

Users running Java SE with a browser can download the latest release from java.com: Java + You. Users on the Windows and Mac OS X platforms can also use automatic updates to get the latest release.

The latest JavaFX release is included with the latest update of JDK and JRE 7. For JDK and JRE 6 users, the latest Java FX release is available
from External_BreadCrumb

References - Oracle Java SE Critical Patch Update Advisory - April 2013

Revision History - April 17, 2013: Initial release

Relevant URL(s):

External_BreadCrumb
java.com: Java + You
Java SE Downloads
Oracle Java SE Critical Patch Update - April 2013

__________________________________________________ __________________

Produced by US-CERT, a government organization.
__________________________________________________ __________________

This product is provided subject to this Notification - Notification | US-CERT

Privacy & Use policy - US-CERT Website Policies and Terms of Use | US-CERT

This document can also be found at - Oracle has released multiple updates for Java SE | US-CERT

For instructions on subscribing to or unsubscribing from this mailing list, visit Mailing Lists and Feeds | US-CERT
 

Top Member Reactions

Users who are viewing this thread

Latest Discussions

Top