Patch/Configuration Management, Vulnerability Management

Apple fixes Java vulnerabilities

Apple has released a new version of Java to resolve 18 vulnerabilities.


The flaws could be exploited by attackers to bypass security restrictions and escalate privileges to gain system access or launch DoS attacks, according to Secunia, which ranked the bugs “highly critical.”


According to an Apple advisory, users should upgrade to Java Release 6 for Mac OS X 10.4.


The vulnerabilities are found in Java 1.4 and J2SE (Java Runtime Environment) 5.0, which allows users to run Java applications. The remaining vulnerability relates to an access flaw in Keychain, Apple's password management system.


The Leopard operating system, released in late October, includes the fixes, many of which had already been patched by Sun Microsystems, the creator of Java.


Many Java developers have turned to the Mac platform. OS X is the only major consumer operating system to come packaged with a complete Java runtime and development environment, according to Apple.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms and Conditions and Privacy Policy.