3 Billion Devices Run (Vulnerable) Java
Sep. 26th, 2012 12:55 pmThe newly discovered bug is special for several reasons. This is our "anniversary" finding (Issue number 50). We discovered it exclusively for JavaOne 2012 [1]. Finally, the bug allows to violate a fundamental security constraint of a Java Virtual Machine (type safety). The following Java SE versions were verified to be vulnerable: - Java SE 5 Update 22 (build 1.5.0_22-b03) - Java SE 6 Update 35 (build 1.6.0_35-b10) - Java SE 7 Update 7 (build 1.7.0_07-b10) All tests were successfully conducted in the environment of a fully patched Windows 7 32-bit system and with the following web browser applications: - Firefox 15.0.1 - Google Chrome 21.0.1180.89 - Internet Explorer 9.0.8112.16421 (update 9.0.10) - Opera 12.02 (build 1578) - Safari 5.1.7 (7534.57.2)
http://seclists.org/fulldisclosure/2012/Sep/170 it's official :)