LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - News > Syndicated Linux News
User Name
Password
Syndicated Linux News This forum is for the discussion of Syndicated Linux News stories.

Notices


Reply
  Search this Thread
Old 01-17-2013, 03:00 PM   #1
LXer
LXer NewsBot
 
Registered: Dec 2005
Posts: 128,502

Rep: Reputation: 118Reputation: 118
LXer: $5,000 will buy you access to another, new critical Java vulnerability (Updated)


Published at LXer:

An exploit for yet another critical Java software vulnerability began circulating online amid reports that the patch Oracle issued two days ago is incomplete."Based on our analysis, we have confirmed that the fix for CVE-2013-0422 is incomplete," Trend Vulnerability Research Manager Pawan Kinger wrote in a blog post. Kinger went on to explain that the vulnerability stemmed from flaws in two parts of the Java code base: one involving the findclass method and the other involving the invokeWithArguments() method. While Sunday's patch fixed the latter issue, the findclass method can still be used to get references to restricted classes, leaving a hole that attackers can exploit.

Read More...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Critical Java vulnerability made possible by earlier incomplete patch LXer Syndicated Linux News 0 01-12-2013 03:12 PM
LXer: Critical Java zero-day bug is being “massively exploited in the wild” (Updated) LXer Syndicated Linux News 1 01-12-2013 04:44 AM
LXer: Critical vulnerability in Ruby on Rails parameter parsing LXer Syndicated Linux News 0 01-09-2013 09:10 AM
LXer: Mozilla confirms critical vulnerability in Firefox 3.5 LXer Syndicated Linux News 0 07-15-2009 06:00 PM
LXer: Rumours of critical vulnerability in OpenSSH in Red Hat Enterprise Linux LXer Syndicated Linux News 0 07-08-2009 11:20 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - News > Syndicated Linux News

All times are GMT -5. The time now is 01:12 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration