Another Java Security Flaw Appears After Oracle Patch

Researchers have uncovered another potentially Java security flaw, which could be used by hackers to serve up malware, almost immediately after Oracle fixed a dangerous weakness.

Oracle issued an out-of-band Java securitypatch last week, after calls  to address a zero-day flaw found by Polish firm Security Explorations. However, days after the patch was issued, Security Explorations was able to find another Java security issue which gets round security protections in Java 7.

Total exploitation

“The new flaw when combined with some previous, not yet addressed issues (reported in April) makes it possible again to completely compromise Java security,” Adam Gowdiak, CEO of Security Explorations, told TechWeekEurope.

“We reported this new issue on Friday and Oracle confirmed the reception of our report and proof of concept code on the same day. The company is conducting the analysis now and should get back with the results once the investigation of the new issue completed.

“We may either see a fix released [in] another out-of-band patch or a Java CPU scheduled for October.”

Security Explorations has decided not to release information on the flaw, following the uncodified rules of responsible disclosure. Oracle had not responded to a request for comment at the time of publication.

Oacle can now expect yet more pressure from the security community to issue a fix, ahead of the scheduled Java update on 16 October.

Are you a security guru? Try our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Programmer Sentenced To Five Years In Prison For Bitcoin Laundering

Ilya Lichtenstein sentenced to five years in prison for hacking into a virtual currency exchange…

2 mins ago

Hate Speech Watchdog CCDH To Quit Musk’s X

Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…

17 hours ago

Meta Fined €798m Over Alleged Facebook Marketplace Violations

Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…

18 hours ago

Elon Musk Rebuked By Italian President Over Migration Tweets

Elon Musk continues to provoke the ire of various leaders around the world with his…

19 hours ago

VW, Rivian Launch Joint Venture, As Investment Rises To $5.8 Billion

Volkswagen and Rivian officially launch their joint venture, as German car giant ups investment to…

20 hours ago

AMD Axes 4 Percent Of Staff, Amid AI Chip Focus

Merry Christmas staff. AMD hands marching orders to 1,000 employees in the led up to…

23 hours ago