Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Government grade malware in the wild

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion
Register FAQ Community Calendar

Oracle to plug 113 security holes in July critical patch update
Reply
 
Thread Tools
Old 14-07-2014, 17:48   #1
Qtx
CF's Worst Nightmare
 
Join Date: May 2012
Location: Probably outside the M25
Services: Sky Fibre Unlimited 40/10
Posts: 3,473
Qtx has a bronzed appealQtx has a bronzed appeal
Qtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appeal
Oracle to plug 113 security holes in July critical patch update

Quote:
ORACLE EXPECTS to release a whopping 113 bug patches to fix a variety of vulnerabilities as part of its monthly security bulletin, the firm said in its Critical Patch Update Pre-Release Announcement for July.

Set to arrive on Tuesday 15 July, the update includes fixes for 20 vulnerabilities in Java SE, all of which can be exploited by an attacker remotely without the need for login credentials.

29 of the fixes are for Oracle's Fusion Middleware suite, with 27 able to be exploited over a network without the need for a username and password. Affected middleware components include BI Publisher, Glassfish Server, HTTP Server, Jdeveloper, Webcenter Portal and Weblogic Server.

Another 15 of the critical patch update fix Oracle's virtualisation software, eight of which are vulnerabilities that also can be remotely exploitable without authentication. Another 10 fixes patch Oracle MySQL
From TheInquirer

TL;DR - If you are a Java developer or use other Oracle software, check for patches tomorrow.

These Java type of holes can be exploited to install trojans or whatever simply by you visiting a website with your browser. Assuming from the info that Java JRE, which is the version home users tend to have, doesn't have the issue. But might be worth checking for updates anyway.
Qtx is offline   Reply With Quote
Advertisement
Old 14-07-2014, 21:22   #2
qasdfdsaq
cf.mega poster
 
Join Date: Aug 2004
Posts: 11,207
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
Re: Oracle to plug 113 security holes in July critical patch update

I know some people running Glassfish server without a password anyway >_>
qasdfdsaq is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 06:27.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.