PDA

View Full Version : Apple and Mozilla Block Vulnerable Java Plug-ins



wraggster
January 12th, 2013, 21:57
Following news that a Java 0-day has been rolled into exploit kits (http://www.us-cert.gov/current/#us_cert_releases_oracle_java), without any patch to fix the vulnerability, Mozilla and Apple have blocked the latest versions of Java on Firefox and Mac OS X respectively. Mozilla has taken steps to protect its user base from the yet-unpatched vulnerability. Mozilla has added to its Firefox add-on block-list (https://blog.mozilla.org/security/2013/01/11/protecting-users-against-java-vulnerability/): Java 7 Update 10, Java 7 Update 9, Java 6 Update 38 and Java 6 Update 37. Similar steps have also been taken by Apple; it has updated its anti-malware system to only allow version 1.7.10.19 or higher (http://paritynews.com/security/item/556-apple-blocks-vulnerable-java-7-plug-in), thereby automatically blocking the vulnerable version, 1.7.10.18."Here are some ways to disable Java (http://www.pcmag.com/article2/0,2817,2414191,00.asp), if you're not sure how.

http://apple.slashdot.org/story/13/01/11/2024222/apple-and-mozilla-block-vulnerable-java-plug-ins