Apple Fixes Java Security Issues

Apple today issued Java for Mac OS X v10.5 Update 4 and Java for Mac OS X v10.4, Release 9 to patch the following security problems:

  • Multiple vulnerabilities exist in Java 1.6.0_07, the most serious of which may allow an untrusted Java applet to obtain elevated privileges. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues are addressed by updating Java 1.6 to version 1.6.0_13. Further information is available via the Sun Java website at http://java.sun.com/javase/6/webnotes/ReleaseNotes.html
  • Multiple vulnerabilities exist in Java 1.5.0_16, the most serious of which may allow an untrusted Java applet to obtain elevated privileges. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues are addressed by updating Java 1.5 to version 1.5.0_19. Further information is available via the Sun Java website at http://java.sun.com/j2se/1.5.0/ReleaseNotes.html
  • Multiple vulnerabilities exist in Java 1.4.2_18, the most serious of which may allow an untrusted Java applet to obtain elevated privileges. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues are addressed by updating Java 1.4 to version 1.4.2_21. Further information is available via the Sun Java website at http://java.sun.com/j2se/1.4.2/ReleaseNotes.html
  • Untrusted Java applets may obtain elevated privileges Description: Multiple vulnerabilities in the “Aqua Look and Feel for Java” implementation may allow an untrusted Java applet to obtain elevated privileges. Visiting a web page containing a maliciously crafted Java applet may lead to arbitrary code execution with elevated privileges. This update addresses the issues by denying access to internal details of Aqua Look and Feel for untrusted Java applets. This issue only affects Java 1.5 on Mac OS X v10.5 systems.

Source: Macintouch

Leave a Reply