========================================================================== Ubuntu Security Notice USN-1693-1 January 16, 2013 openjdk-7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 Summary: OpenJDK 7 could be made to crash or run programs as your login if it opened a specially crafted Java applet. Software Description: - openjdk-7: Open Source Java implementation Details: It was discovered that OpenJDK 7's security mechanism could be bypassed via Java applets. If a user were tricked into opening a malicious website, a remote attacker could exploit this to perform arbitrary code execution as the user invoking the program. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: icedtea-7-jre-cacao 7u9-2.3.4-0ubuntu1.12.10.1 icedtea-7-jre-jamvm 7u9-2.3.4-0ubuntu1.12.10.1 openjdk-7-jre 7u9-2.3.4-0ubuntu1.12.10.1 openjdk-7-jre-headless 7u9-2.3.4-0ubuntu1.12.10.1 openjdk-7-jre-lib 7u9-2.3.4-0ubuntu1.12.10.1 openjdk-7-jre-zero 7u9-2.3.4-0ubuntu1.12.10.1 After a standard system update you need to restart your browser to make all the necessary changes. References: http://www.ubuntu.com/usn/usn-1693-1 CVE-2012-3174, CVE-2013-0422 Package Information: https://launchpad.net/ubuntu/+source/openjdk-7/7u9-2.3.4-0ubuntu1.12.10.1
Spotlight

The security of WordPress plugins
Posted on 18 June 2013. | Checkmarx’s research lab identified that more than 20% of the 50 most popular WordPress plugins are vulnerable to common Web attacks, such as SQL Injection.

Information security executives need to be strategic thinkers
Posted on 17 June 2013. | George Baker, the Director of Information Security at Exostar, talks about the challenges in working in a dynamic threat landscape, offers tips for aspiring infosec leaders, and more.

Large orgs in denial about own security breaches?
Posted on 14 June 2013. | Over two thirds (66%) of large organizations said they either had not experienced a security incident in the last 12-18 months or were unsure if they had.

Vulnerability scanning with PureCloud
Posted on 12 June 2013. | nCircle PureCloud is a cloud-based network security scanning product built upon the companies' vulnerability and risk management system IP360.

Reactions from the security community to the NSA spying scandal
Posted on 11 June 2013. | Read on for comments on this scandal that Help Net Security received from a variety of security professionals and analysts.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.


