Showing posts with label Oracle Emergency patch. Show all posts
Showing posts with label Oracle Emergency patch. Show all posts

Wednesday, March 6, 2013

Emergency patch zero-day vulnerabilities in Java


Oracle has released an emergency patch zero-day vulnerabilities in Java


The company violated the second time release schedule updates, due to frequent hacking attacks.

On Monday, March 4, Oracle has introduced an unscheduled update Java 7 Update 17 and Java 6 Update 43 to fix two critical vulnerabilities in Java, one of which hackers use to carry out targeted attacks.

Exploits CVE-2013-1493 and CVE-2013-0809, which exist because of errors in sub-component 2D, received from Oracle highest danger level (CVSS Score 10.0).

Vulnerability can be exploited remotely by unauthorized users. An attacker can execute arbitrary code on the target system.