Contact Us Today! (215) 853-2266

Bardissi Enterprises Blog

Bardissi Enterprises has been serving the Hatfield area since 2000, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

WatchGuard: Apple Sneaks Out Java Updates for OS X

Severity: Medium

25 September, 2008


Summary:

§This vulnerability affects: OS X 10.4.x (Tiger) and 10.5.x (Leopard)

§How an attacker exploits it: By enticing your users to a malicious web site

§Impact: In the worst case, an attacker executes code on your user’s computer, potentially gaining control of it

§What to do: Install Java for OS X 10.4 Release 7 or Java for OS X 10.5 Update 2 as soon as possible

Severity: Medium

25 September, 2008


Summary:

§This vulnerability affects: OS X 10.4.x (Tiger) and 10.5.x (Leopard)

§How an attacker exploits it: By enticing your users to a malicious web site

§Impact: In the worst case, an attacker executes code on your user’s computer, potentially gaining control of it

§What to do: Install Java for OS X 10.4 Release 7 or Java for OS X 10.5 Update 2 as soon as possible

Exposure:

Amidst all the noise created by Cisco and Mozilla yesterday, Apple quietly issued two alerts [ 1 / 2 ] updating the Java components that ship with OS X 10.4 and 10.5. The alerts describe several vulnerabilities in OS X’s Java components. They describe some of the vulnerabilities in detail, while leaving others unexplained. Despite their technical differences, the worst of these Java vulnerabilities all share the same potential impact: Specifically, an attacker can exploit many of these Java flaws to either execute code or elevate privileges on your users’ OS X computers. In order to exploit these vulnerabilities, the attacker would simply have to lure one of your OS X users into visiting a malicious web page containing specially crafted Java code.

Solution Path:

Apple has issued Java Release 7 for OS X 10.4 and Java for OS X 10.5 Update 2 to correct these flaws. If you manage OS X computers, we recommend you download, test and deploy these updates as soon as possible.

OS X’s Software Update utility automatically detects updates such as this one for OS X and then informs you, so that you can install the update as soon as possible. We recommend that you set up Software Update to check for new updates daily, and allow it to assist you in keeping your Apple software current.

For All WatchGuard Users:

Some of these attacks rely on one of your users visiting a web page containing malicious Java bytecode. The HTTP-Proxy policy that ships with most Firebox models automatically blocks Java bytecode by default. If you manage a Firebox with its default HTTP-Proxy, your users will not be able to download the malicious code needed to trigger some of these vulnerabilities.

Status:

Apple has released Java Release 7 for OS X 10.4 and Java for OS X 10.5 Update 2, which fixes these issues.

References:

§Apple’s OS X 10.4 Java alert

§Apple’s OS X 10.5 Java alert

§Apple software downloads

§Apple security updates

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Monday, 25 November 2024
If you'd like to register, please fill in the username, password and name fields.

Captcha Image

Mobile? Grab this Article!

QR-Code dieser Seite

Blog Archive

Recent Comments

Tip of the Week: Which Headphones are Right for Your Needs?
23 April 2018
I will recommend Plantronics Backbeat Pro 2 SE Noise cancelling Headset with it's Great features.
Gamification: Make Business Fun for Everyone
27 January 2017
The world is based on the games. There are many types of games as per the aussie essay writing servi...
Let's Talk Tablets
12 January 2017
The concept of tablet is far better than that of PC because you can bring them with you everywhere a...
Tip of the Week: Tweak Your Workday in These 4 Ways and See Major Results
12 January 2017
The only thing will I will say regarding this blog is that it is very helpful at least for me. As I ...
WatchGuard Releases Version 10.2.7 for WSM, Edge, Fireware, and Fireware Pro
23 December 2016
I really needed to know about the fireware but i was confused that where can i find information abou...