Showing posts with label Oracle. Show all posts
Showing posts with label Oracle. Show all posts

Oracle ships giant raft of patches - but none of them for Java

Oracle's latest Patch Tuesday has come and gone, with the database-and-more behemoth putting out patches for 89 vulnerabilities.
Twelve products sets in the Oracle stable get from 1 to 21 patches each. These squash a total of 45 RCEs, or Remote Code Execution vulnerabilities.

http://nakedsecurity.sophos.com/2013/07/17/oracle-ships-giant-raft-of-patches-but-none-of-them-for-java/
Oracle ships giant raft of patches
In Oracle's own words, which are actually well chosen and plainly put, RCEs are defined as:
vulnerabilities [that] may be remotely exploitable without authentication, i.e., may be exploited over a network without the need for a username and password.
Oracle ships giant raft of patches - but none of them for Java | Naked Security

Reporting security flaws for OpenJDK 6

Oracle has announced that it no longer provides public updates to their proprietary Oracle Java SE 6, as of February 2013. These updates, which may include security patches, are now only available to users of Oracle Java SE 6 who have a commercial support agreement with Oracle. Users who have a need for support on Java SE 6 and are not willing to consider commercial support from Oracle have another choice.

http://securityblog.redhat.com/2013/07/03/reporting-security-flaws-for-openjdk-6/
Security flaws for OpenJDK 6
Red Hat recently assumed a leadership role for the OpenJDK 6 project. OpenJDK is an open source and community supported implementation of the Java SE specification. Red Hat maintains its role in setting the future direction for the OpenJDK project as an active board member, represented by Red Hat’s long-time Java technical lead, Andrew Haley. OpenJDK 6 will continue to receive security fixes with the help of Red Hat’s stewardship and collaboration with the larger OpenJDK community.