<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Yet another Java security flaw discovered - Number 53&#x27; in forum &#x27;Security&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Yet-another-Java-security-flaw-discovered-Number-53-27958880</link>
<description></description>
<language>en</language>
<pubDate>Sun, 19 May 2013 15:52:53 EDT</pubDate>
<lastBuildDate>Sun, 19 May 2013 15:52:53 EDT</lastBuildDate>

<item>
<title>Re: Yet another Java security flaw discovered - Number 53</title>
<link>http://www.dslreports.com/forum/Re-Yet-another-Java-security-flaw-discovered-Number-53-27960589</link>
<description><![CDATA[chrisretusn posted : True. That was my point. It was an unnecessary addition to the headline. <br><br>Same as Yet another Firefox security flaw discovered - Number... who cares. <br><br>It's really getting old this play on Java. <br><small>--<br>Chris<br><b>Living in Paradise!!</b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Yet-another-Java-security-flaw-discovered-Number-53-27960589</guid>
<pubDate>Wed, 30 Jan 2013 04:25:34 EDT</pubDate>
</item>

<item>
<title>Re: Yet another Java security flaw discovered - Number 53</title>
<link>http://www.dslreports.com/forum/Re-Yet-another-Java-security-flaw-discovered-Number-53-27960572</link>
<description><![CDATA[NOYB posted :  <br>Quantity is only one vector.  And not necessarily the most important.  Exploit severity is another and likely more important.<br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Yet-another-Java-security-flaw-discovered-Number-53-27960572</guid>
<pubDate>Wed, 30 Jan 2013 03:38:40 EDT</pubDate>
</item>

<item>
<title>Re: Yet another Java security flaw discovered - Number 53</title>
<link>http://www.dslreports.com/forum/Re-Yet-another-Java-security-flaw-discovered-Number-53-27960518</link>
<description><![CDATA[chrisretusn posted : Ok so there is another one. <br><br>According to <A HREF="http://www.cvedetails.com/product-search.php?vendor_id=0&search=jre" >CVE Details</A> is more than that. <br><br>1 	JRE		SUN		303 	(2001-2012) (46 in 2012)<br>2 	JRE		Oracle	64 	(2010-2013) (58 in 2012, 2 in 2013)<br><br>Firefox had 162 in 2012, 27 so far in 2013. &raquo;<A HREF="http://www.cvedetails.com/product/3264/Mozilla-Firefox.html?vendor_id=452" >www.cvedetails.com/product/3264/&middot;&middot;&middot;r_id=452</A><br><br>Chrome had 248 in 2012, 29 so far in 2013. &raquo;<A HREF="http://www.cvedetails.com/product/15031/Google-Chrome.html?vendor_id=1224" >www.cvedetails.com/product/15031&middot;&middot;&middot;_id=1224</A><br><small>--<br>Chris<br><b>Living in Paradise!!</b></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Yet-another-Java-security-flaw-discovered-Number-53-27960518</guid>
<pubDate>Wed, 30 Jan 2013 02:19:16 EDT</pubDate>
</item>

<item>
<title>Yet another Java security flaw discovered - Number 53</title>
<link>http://www.dslreports.com/forum/Yet-another-Java-security-flaw-discovered-Number-53-27958880</link>
<description><![CDATA[kickass69 posted : &raquo;<A HREF="http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53" >blogs.computerworld.com/malware-&middot;&middot;&middot;umber-53</A><br><br>&raquo;<A HREF="http://seclists.org/fulldisclosure/2013/Jan/241" >seclists.org/fulldisclosure/2013/Jan/241</A><br><br>"JAVA FLAW NUMBER 53 <br> <br>And that's where things stood until today, when I received an email from Adam Gowdiak pointing me to his latest discovery of, yet another Java bug. Ironically, the bug is with the new security improvements Mr. Smith alluded to. <br> <br>As is the normal pattern, this new flaw involves running unsigned Java programs embedded in web pages.<br> <br>Java 7 Update 10 introduced the new security rules for unsigned applets, and Update 11 made the default more secure. But, it turns out that the rules are not rules, they're not even suggestions. Gowdiak referred to them as theories. <br> <br>He writes <br><br>    What we found out and what is a subject of a new security vulnerability (Issue 53) is that unsigned Java code can be successfully executed on a target Windows system regardless of the four Java Control Panel settings ...  <br><br>Whereas I found that Internet Explorer would ignore the new security rules, Gowdiak's discovery is much broader. We approached things differently. I tested with safe Java applets, he purposely wrote a malicious one. <br> <br>Via email, Gowdiak wrote that "We found a generic way to bypass the new security settings imposed by Java Control Panel that control the launch of unsigned Java code." <br> <br>In other words, his malicious unsigned applet can do its dirty work in all browsers. On Windows 7, he tested the latest version of Internet Explorer 9, Firefox 18.0.1, Opera 12.12 and Google Chrome 24.0.1312.56m.<br> <br>Also, since I was using safe applets, Java had to be tweaked a couple times before the rules were ignored (the end user had to first disable Java in browsers via the Java Control Panel, then later re-enable it). Not so with Gowdiak's malicious applet, which can run without warning on the "Very High" setting, even if Java has not been tweaked and even if the "Very High" setting is blocking other applets.<br><br> In the conclusion of his Full Disclosure mailing list posting, Gowdiak wrote <br><br>    "... recently made security "improvements" to Java SE 7 software don't prevent silent exploits at all. Users that require Java content in the web browser need to rely on a Click to Play technology implemented by several web browser vendors in order to mitigate the risk of a silent Java Plugin exploit."<br><br>Anymore reasons one needs to uninstall if possible and disable otherwise?  Atleast Firefox and *shudder* Chrome use Click to Play atleast for those of us who use Java.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Yet-another-Java-security-flaw-discovered-Number-53-27958880</guid>
<pubDate>Tue, 29 Jan 2013 15:27:34 EDT</pubDate>
</item>

</channel>
</rss>
