Java vulnerabilities, already patched by Oracle !
Vulnerabilities have been discovered in Java.
According to the official document of the alert, the vulnerabilities are:
- An error in the code of the class HeadspaceSoundbank can cause a buffer overflow via a specially crafted file Soundbank;
- An error in the processing of images can cause a buffer overflow via a specially crafted Java applet;
- Several other unspecified vulnerabilities exist in Oracle Java components.
These flaws could allow remote execution of malicious code or open a door to a denial of service attack. Confidential records are no longer protected optimally.
The JVM impacted are:
- Java SE JDK / JRE 6 Update 18 and earlier for Windows, Solaris, and Linux;
- Java SE JDK 5.0 Update 23 and earlier for Solaris;
- Java SE SDK 1.4.2_25 and earlier for Solaris;
- Java for Business, JDK / JRE 6 Update 18 and earlier for Windows, Solaris, and Linux;
- Java for Business, JDK / JRE 5.0 Update 23 and earlier for Windows, Solaris, and Linux;
- Java for Business, SDK / JRE 1.4.2_25 and earlier for Windows, Solaris, and Linux.
These reports were confirmed by Oracle that provides security updates to this address.
Source : CERTA alert
Sun VirtualBox 3.1.6 update
VirtualBox 3.1.6 is out. Nothing really new to the program if it is slightly improved stability and fixed many bugs.
The virtualization of Linux distributions has also been central to the efforts of development teams.
In short, this is a minor update. But who sends a major message. The virtualization solution from Sun continues to enjoy the support of the new company owner. In other words, Oracle will take an indirect response to those who worried about the future of VirtualBox after the takeover of the publisher.
VirtualBox 3.1.6 is available (Windows, Mac, Linux (32 and 64 bit) on this page. The tool is also compatible with Solaris / OpenSolaris.
