Sunday, April 28, 2024
 Popular · Latest · Hot · Upcoming
8
rated 0 times [  8] [ 0]  / answers: 1 / hits: 2184  / 1 Year ago, mon, november 14, 2022, 4:48:52

I was curious to know if OpenJDK is also vulnerable to the Zero-Day Exploit that is currently afflicting Java 7 because of which experts are telling people to disable Java until a solution is found on all operating systems.


More From » 12.10

 Answers
1

update: see Ubuntu Security Notice USN-1693-1




It was discovered that OpenJDK 7's security mechanism could be bypassed via
Java applets. If a user were tricked into opening a malicious website, a
remote attacker could exploit this to perform arbitrary code execution as
the user invoking the program.







Probably not for the specific exploit being used in the wild for Oracle's Java 7 plugin. These exploits are usually specifically crafted to run with a specific set of software.



However, OpenJDK can be vulnerable in a similar way, if it's because of a design/architecture error in the way Java works in a browser. I could not find any details on it (at the time of writing) to support that statement with facts, but previous vulnerabilities were specifically for Oracle's JRE/JDK while OpenJDK has its own.



Please note the difference between an exploit and a vulnerability in this context.



Also note that you are probably affected to some extent if you're running Oracle's JRE/JDK on Ubuntu. However, the exploits are probably targeted for Windows hosts, and Oracle's JRE/JDK is no longer distributed by Ubuntu, due to licensing issues (Oracle doesn't allow redistribution anymore).


[#33233] Wednesday, November 16, 2022, 1 Year  [reply] [flag answer]
Only authorized users can answer the question. Please sign in first, or register a free account.
calronze

Total Points: 0
Total Questions: 110
Total Answers: 112

Location: Belarus
Member since Thu, Aug 11, 2022
2 Years ago
calronze questions
Sun, Jan 9, 22, 13:41, 2 Years ago
Wed, Feb 15, 23, 01:41, 1 Year ago
Sat, Jul 23, 22, 21:03, 2 Years ago
Sat, Feb 5, 22, 01:57, 2 Years ago
;