Email this article   Print article 


Java Vulnerabilities Underscore Cross-Vendor Complexities Of Secure Code

By Ken Presti
November 30, 2012    6:56 PM ET

Page 1 of 2

The Java browser plug-in has been getting a black eye in recent months from security experts who recommend that it be disabled due to a wide range of security exploits inadvertently enabled by the plug-in. As the volume of attacks continues to grow, a number of people have begun to suggest that, if the plug-in was not specifically necessary, most machines would be better off without it.

Recent Java exploits include a vulnerability in Java JRE 7 Update 9 that enables remote code execution and is currently being sold on the black market for an undisclosed price.

"Java is a major threat vector today," said Paul Henry, security and forensics expert at Lumension. "But we also have to understand why they are such a major threat vector. People have historically done a poor job of patching Java, which is understandable to some extent because when you patch Java, it might affect your application. The bad guys understand this, and therefore they are looking for exploits. If you go back a year ago, they were focusing on Adobe Flash. But, Adobe started patching more frequently and so the attention has turned to Java. We have recommended in the past that you should disable it when you're waiting for patches. But once you get those patches, you can re-enable it."

[Related: Whitelisting May Be The Key Security Strategy For Java]

Despite a relatively lengthy patch cycle, Henry says that Oracle does a relatively good job of pushing-out unscheduled, out-of-band patches when vulnerabilities become publicized and used in the wild. But in many cases, other vendors that use Java within their own products are less diligent in plugging the holes.

"Apple is a perfect example," said Henry. "We had an issue a few months back with three known vulnerabilities for which Oracle pushed out patches. But, Apple only included one of those patches in their updates, leaving people exposed for quite some time."

Henry pointed to Microsoft as an example of a company that has made great improvements in addressing security issues, and he recommended that Apple examine the Microsoft model more closely. "Apple needs to investigate what's been done by Microsoft, but Apple will never want to do anything like Microsoft," he said.

Developing security patches for software is a significant challenge, according to Marcus Carey, security researcher at Rapid7.

"I think it highlights how hard it is to keep software secure, especially when you have to support so many platforms and so many browsers," said Carey. "It doesn't mean that Oracle is doing a horrible job in supporting security for the Java plug-ins. It's just hard to put up software that is secure."

NEXT: A Constant Barrage

1 | 2 | Next >>

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Tech 10: Hot Antivirus Alternatives For 2013

CRN identifies 10 vendors that have developed innovative ways to detect malware and analyze threats to better protect corporate networks. They take a giant step beyond traditional signature technologies.

10 Emerging Security Technologies Gaining Interest, Adoption

Despite some security defenses being only in their infancy, they are attracting interest for addressing BYOD issues, cloud security concerns and stolen account credentials. Here's a look at some of the top new security areas gaining industry interest.

5 Government Intelligence Facilities You've Never Heard Of

One facility has been around since the dawn of space exploration, while other buildings are still in construction. But, they all have serious data analysis and surveillance support activities associated with them.

  More Slide Shows




Related Videos
Loading...