http://arstechnica.com/security/2012/08/critical-bug-discovered-in-newest-java/
Researchers said they've uncovered a flaw in the Java 7 update
released by Oracle on Thursday that allows attackers to take complete
control of end-user computers.
--To view this discussion on the web visit https://groups.google.com/d/msg/javaposse/-/GlpkcwBwN9wJ.
You received this message because you are subscribed to the Google Groups "Java Posse" group.
To post to this group, send email to java...@googlegroups.com.
To unsubscribe from this group, send email to javaposse+...@googlegroups.com.
For more options, visit this group at http://groups.google.com/group/javaposse?hl=en.
Unfortunately, it seems that Oracle will wait 4 months with patching this hole:
--
You received this message because you are subscribed to the Google Groups "Java Posse" group.
To view this discussion on the web visit https://groups.google.com/d/msg/javaposse/-/8BrcJEa3reoJ.
Oh no! A security firm is advertising somebody trying to make money by selling a patch to an exploit without providing any link to said sale (conveniently posted on a for-pay web site) nor evidence to back up their claim.
What are we gonna do? What are we gonna do?
"The flaw, currently being sold by an established member of an invite-only Underweb forum,"
--
You received this message because you are subscribed to the Google Groups "Java Posse" group.
This is mostly hinged on my belief that the selling of exploits is not actually unheard of.
In any event, the exploit has now made it into the known exploit kits Blackhole and NuclearPack, so a new wave of JVM security exploits now seems eminent:
--
You received this message because you are subscribed to the Google Groups "Java Posse" group.
To view this discussion on the web visit https://groups.google.com/d/msg/javaposse/-/6fFk5pAxFd0J.