Risky Java software: Oracle issues emergency fix to thwart hackers

Days after the US issued a security alert to millions of computer owners to temporarily disable Java, Oracle released an emergency fix to its product and urged it be made as soon as possible.

This 2007 file photo shows the Java logo at Sun Microsystems' offices in Menlo Park, Calif. Oracle has released a security update for its Java product, after the US Department of Homeland Security issued an alert warning millions of computer users of a high risk of cyberattack.

Paul Sakuma/AP/File

January 14, 2013

Software giant Oracle has released a security update for its widely used Java product, after the US Department of Homeland Security issued an alert warning millions of computer users of a high risk of cyberattack.

The department had encouraged computer users to disable Java, software that frequently runs in the background when computers are browsing the Internet. As of late last week, malicious software "kits" were available for criminals to use in exploiting the Java security gap.

"Due to the severity of these vulnerabilities ... Oracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible," the company said in announcing the fix.

Why many in Ukraine oppose a ‘land for peace’ formula to end the war

To implement Oracle's fix, you can visit the Java update or Java download pages. On the update page, see the "update manually" link near the top. Following the instructions may require that you go to your computer's control panel and type "Java" in a search bar, to open a Java control panel. Then you can click a tab labeled "update."

Oracle accompanied its fix with another change: The updated version's default security setting is now "high" rather than "medium," so that users will be asked to sign off case by case on many Java activities. Users will be "prompted before any unsigned Java applet or Java Web Start application is run," Oracle said.

Even after Oracle's move, many experts on computer security say Java software remains vulnerable to hackers.

Hacker-response experts at the group CERT, based at Carnegie Mellon University, continue to view Java as high-risk software, even with the new patch installed.

"Unless it is absolutely necessary to run Java in web browsers, disable it as described below, even after updating" to the newly released Java 7 Update 11, a CERT vulnerability notice says. "This will help mitigate other Java vulnerabilities that may be discovered in the future."
A number of independent Web-security analysts are sounding similar notes of caution.

Howard University hoped to make history. Now it’s ready for a different role.

"It’s nice that Oracle fixed this vulnerability so quickly," writes Internet security blogger Brian Krebs. But "it seems malware writers are constantly finding new zero-day vulnerabilities in Java."

A "zero-day" attack is one that exploits a vulnerability that has not been documented before, so defenders have had zero days to develop security patches.

"Most users who have Java installed can get by just fine without it," Mr. Krebs wrote Sunday, as Oracle unveiled its Java update. "If you need Java for a specific Web site, consider adopting a two-browser approach. If you normally browse the Web with Firefox, for example, consider disabling the Java plugin in Firefox, and then using an alternative browser ... with Java enabled to browse only the site(s) that require(s) it."

Some experts on personal-computer security say Java may need to be rewritten from the ground up. Bogdan Botezatu, a threat analyst at Bitdefender, a Romanian-based maker of antivirus software, made this case in an interview with PCWorld published Jan. 12. He said the problem with mature and widely used products like Java and those made by Adobe is that their code has been revised so many times by so many people over the years.

"These products have become so large and have been developed by so many programmers that the makers have most probably lost control over what's in the product," Mr. Botezatu told PCWorld.

The Department of Homeland Security's cyber division, called US-CERT (Computer Emergency Readiness Team) issued the alert about Java late last week. Information about how to disable Java or to limit the software's activity was posted over the weekend by the Monitor and a range of other publications.