dslreports logo
Search similar:


uniqs
3726

chachazz
Premium Member
join:2003-12-14
kudos:10
·TELUS

1 edit

chachazz

Premium Member

Java Critical Patch Update - October 14, 2014

Oracle Critical Patch Update for October 2014, which will be released on Tuesday, October 14, 2014 - »www.oracle.com/technetwo ··· 960.html

This Critical Patch Update contains 25 new security fixes for Oracle Java SE.
22 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password.

The highest CVSS Base Score of vulnerabilities affecting Oracle Java SE is 10.0

The Oracle Java SE components affected by vulnerabilities that are fixed in this Critical Patch Update are:
• Java SE
• Java SE Embedded
• JavaFX
• JRockit

Affected versions:
Oracle Java SE, versions 5.0u71, 6u81, 7u67, 8u20
Oracle JavaFX, version 2.2.65
Oracle Java SE Embedded, version 7u60

Java SE 8 runtime (JRE) updates will be available here: (Java 8 update 25)
»java.com/en/download/manual.jsp
-or-
»www.oracle.com/technetwo ··· dex.html

Java SE 7 runtime (JRE)updates will be available here: (Java 7 update 71/72)
»www.oracle.com/technetwo ··· dex.html

Edit: links & versions noted

CovMac
Premium Member
join:2000-11-06
Covington, LA

CovMac

Premium Member

Guess I need to wait later in the day. The link to the SE 7 update still shows 7u67 as the recommended version.
GuruGuy
join:2002-12-16
Atlanta, GA

GuruGuy

Member

said by CovMac:

Guess I need to wait later in the day. The link to the SE 7 update still shows 7u67 as the recommended version.

OP is Oct 11th and a heads-up. Post will be updated once patches are available.
GuruGuy

GuruGuy to chachazz

Member

to chachazz
Clicking the 7 link nows shows this:

Java Downloads for All Operating Systems
Recommended Version 8 Update 25

Looks like they are finally pushing ver 8
GuruGuy

GuruGuy

Member

said by GuruGuy:

Clicking the 7 link nows shows this:

Java Downloads for All Operating Systems
Recommended Version 8 Update 25

Looks like they are finally pushing ver 8

So the question now is will this update 7 to 8 or will you end up with two versions installed.

cbrigante2
Cubs 20??
Premium Member
join:2002-11-22
North Aurora, IL

cbrigante2

Premium Member

said by GuruGuy:

So the question now is will this update 7 to 8 or will you end up with two versions installed.

I ran the normal update as it came up...it installed...then ran the check for older versions and gave me the recommended 8 upgrade path. Running that now to see how it goes.
GuruGuy
join:2002-12-16
Atlanta, GA

GuruGuy

Member

I don't understand what you mean by "running the normal update". I clicked the link for version 7 and there was not version 7 update offered. Only 8.

cbrigante2
Cubs 20??
Premium Member
join:2002-11-22
North Aurora, IL

cbrigante2

Premium Member

Sorry I meant that I got the Java Update Available popup with Java 7 doing it's update check. I ran that..it installed...then popped the browser open to check for old versions and gave me the 8 download (it never did that before)
GuruGuy
join:2002-12-16
Atlanta, GA

GuruGuy

Member

So what version did the internal installer update you to?

cbrigante2
Cubs 20??
Premium Member
join:2002-11-22
North Aurora, IL

cbrigante2

Premium Member

7 Update 71 I think it said?
8 version 25 on the second one (my new current)
GuruGuy
join:2002-12-16
Atlanta, GA

GuruGuy to chachazz

Member

to chachazz
After some digging, I found the update for 7.

»java.com/en/download/man ··· ava7.jsp

Recommended Version 7 Update 71

"Java SE 7 End of Public Updates Notice After April 2015, Oracle will no longer post updates of Java SE 7 to its public download sites. Existing Java SE 7 downloads already posted as of April 2015 will remain accessible in the Java Archive on Oracle Technology Network. » Java 7 FAQ"

Someone has screwed up again by hiding it. My calendar says it's Oct 14th 2014. It definitely is not April 2015
GuruGuy

GuruGuy to chachazz

Member

to chachazz
Ok, another eff up.
Clicking the 7 link »java.com/en/download/manual.jsp and seeing the suggested version for 8.....and then clicking the offline 64 bit version redirects to this page:

»sdlc-esd.sun.com/ESD6/JS ··· .sun.com

a screenshot of open office banner
GuruGuy

GuruGuy

Member

And now someone has fixed it and it works...

a non entity
@71.36.59.x

a non entity

Anon

The 'Verify Java version and check for out-of-date-versions' page seems to be now fixed and after updating Java 7u67 to 7u71, it no longer pushes the v 8u25 version.

So if you are on v7u71 you are indicated as 'up-to-date'....unless you choose to move on to v8u25 at your discretion.

andyross
MVM
join:2003-05-04
Schaumburg, IL
kudos:1

andyross

MVM

Is v8 safe to use now, or does it still not work properly with some web sites and similar?
GuruGuy
join:2002-12-16
Atlanta, GA

GuruGuy

Member

Probably have to wait for Mele to chime in on that one hahaha

Dustyn
Premium Member
join:2003-02-26
Ontario, CAN
kudos:13

Dustyn to chachazz

Premium Member

to chachazz
Thanks for the update!

chachazz
Premium Member
join:2003-12-14
kudos:10

chachazz

Premium Member

You're welcome.

More information on the updates-Oracle Software Security Assurance Blog
https://blogs.oracle.com/security/