Search the web
Sign In
New User? Sign Up
ClubMacMonterey · CMoM - Club Mac of Monterey
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
MacFixIt Article: Apple releases Java update addressing critical vul   Message List  
Reply | Forward Message #228 of 266 |
Jerry wrote: Can we use Java safely again?

This email was sent to you by Jerry at idahogiff@....
This is not SPAM and the email addresses involved in this transaction were not saved to a list or stored for later use.

You are currently logged in as idahogiff@....    Logout?

     

MacFixIt Logo
Advertise | Support | Contact Us
Advanced Search  
Apple releases Java update addressing critical vulnerability
Monday, June 15 2009 @ 03:36 PM PDT

Apple has released an update for Java which addresses the recently announced vulnerability that has apparently been a long-standing bug in Java for OS X. The bug allowed for code and applications to be run as the current user, which could be dangerous if you were logged in as an adminstrator.



We discussed the problem and workarounds in our past article on the issue, but the current updates from Apple should address it completely and prevent the vulnerability from running. After applying the update, we tested the problem with the proof-of-concept java applet that we referenced in our initial article on the issue, and the applet isnt working anymore which indicates the problem has been fixed.

The updates are available via Software Update, and also from Apple's downloads page for both Tiger and Leopard users:

Java for Mac OS X 10.5 Update 4
Information about this update can be found here: http://support.apple.com/kb/HT3581

Java for Mac OS X 10.4, Release 9
Information about this update can be found here: http://support.apple.com/kb/HT3593

The update does not require a restart, but will require you to quit your Web browser and relaunch it for changes to take effect.

While it's been a long time coming, we're glad Apple has tackled this problem. People who have disabled Java in their Web browsers can now re-enable it again after applying this update.

UPDATE: The updates require the latest releases of their respective OS X versions to be installed. As such, people who have not updated to 10.5.7 (or 10.4.11 for Tiger users) will not be able to install this update. If you cannot update to the latest version because of some incompatibility, then we recommend you still keep Java disabled in Safari and other Web browsers.



Comment on this story at
http://www.macfixit.com/article.php?story=20090615153636345#comments
 

Problems with MacFixIt?
Contact support.

MacFixIt provides exclusive troubleshooting content, including renowned special reports on incremental and major Mac OS X releases, e-mail alerts for late breaking items and expert commentary from leading Mac authors. For access to all MacFixIt content, sign up for MacFixIt Pro.


Home | MacFixIt Pro | Search | Forums | Reports | Archives | Library | Email | About | Ads | Links |

VersionTracker: Software Updates and Downloads | iPhone Atlas: iPhone Help, News, Tutorials, and Tips




Tue Jun 16, 2009 6:16 am

grgiff68
Offline Offline
Send Email Send Email

Forward
Message #228 of 266 |
Expand Messages Author Sort by Date

Jerry wrote: Can we use Java safely again? This email was sent to you by Jerry at idahogiff@.... This is not SPAM and the email addresses involved in this...
Jerry
grgiff68
Offline Send Email
Jun 16, 2009
6:16 am
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help