News

Oracle to patch Java vulnerability on short notice

← Back to news

Oracle may release a patch for Java 7 as early as Tuesday to close serious security vulnerabilities.

Oracle is reportedly working on a Java 7 patch that would be part of a major security update on Tuesday fixing a total of 86 vulnerabilities. Among the issues addressed are at least 18 holes in MySQL. The exact timing of the Java fix is not yet entirely certain. Oracle said only this weekend that it would happen “very soon.”

Exploit

Last week, a serious zero-day vulnerability in Java was discovered. An exploit has already surfaced that, after clicking a malware link, allows an attacker to take full control of a PC. The exploit is designed to install ransomware that locks the victim’s computer and makes it accessible only upon payment.

Apple blocks Java

Because of the vulnerability, Apple moved to block the Java plug-in in the anti-malware system in OS X. Mozilla has likewise placed all Java versions on its blacklist.

The U.S. government’s Computer Emergency Readiness Team (US-CERT) also advised all internet users to disable Java in the browser. Java is estimated to run on 850 million computers worldwide.