Exclusive Deal While supplies last, save 40% off over 40 iPhone 5 and iPhone 4/4S cases and chargers as well as Samsung S III cases at Kensington.com. Use coupon code 'SAVE40%' at checkout to receive this exclusive discount.      
toggle

AAPL Stock: 445.15 ( + 3.01 )

http://www.electronista.com/articles/13/03/01/real.world.malware.called.inconsistent/

Researchers discover new, in-use vulnerability in Java

updated 04:06 pm EST, Fri March 1, 2013

 
", 0, 0);

Real-world malware called inconsistent


A new vulnerability has been discovered in the latest versions of Java, v1.6 Update 41 and v1.7 Update 15, say researchers from security firms FireEye and Kaspersky Lab. Critically the bug is already being exploited in order to download and install a remote access tool, "McRAT," on targeted computers. The malware is being spread through a JPG file hosted on a Japanese website.

FireEye remarks that the current exploit is inconsistent. It attempts to break through Java security measures by overwriting a large memory chunk, but sometimes fails to download the malware, instead crashing the Java Virtual Machine. Kasperky meanwhile observes that while the attack works against Java 7 Update 15, it fails against older versions.

This week's discovery represents the third zero-day Java exploit this year, and has forced Oracle to play a cat-and-mouse game, releasing a string of unplanned updates to keep up. Apple has meanwhile taken steps of its own to protect OS X, not only posting Mac-native Java updates, but in some cases blocking Java outright until Oracle can produce a patch.


by MacNN Staff

Post tools:

TAGS :

 security, software, Java
toggle

Comments

  1. Makosuke

    Fresh-Faced Recruit

    Joined: 08-06-01

    Ouch

    It's honestly getting to the point where, if I were a browser vendor, I'd just remove support for a Java plugin from the browser entirely. The tiny number of people who use Java-based applets that you'd annoy would be minuscule compared to the vast number of people you'd benefit, and some niche browser that did support in-window Java would probably take over for the professionals who actually need the feature.

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

MacNN Sponsor

Recent Reviews

MaxUpgrades MaxConnect for 2006-2008 Mac Pro

Nobody outside of Cupertino's privileged bunch knows the future of the Mac Pro line for sure. Despite Apple's reluctance to tell us wh ...

Brother HL-3170CDW LED Printer

We've mentioned before that we are far from a paperless society. For now, at least, there are tasks that require a piece of paper for ...

HTC One

It is hard to overstate just how critically important the HTC One is to the Taiwanese company’s fortunes. Despite its alarming decline ...

toggle

Most Commented