Security-X
Forum Security-X => News => Discussion démarrée par: chantal11 le janvier 13, 2013, 09:58:25
-
Java 0day Mass Exploit Distribution
Just a quick note, it's only the second week of January, but early 2013 brings with it the first Java 0day mass exploit distribution of the year.
There appears to be multiple ad networks redirecting to Blackhole sites, amplifying the mass exploitation problem. We have seen ads from legitimate sites, especially in the UK, Brazil, and Russia, redirecting to domains hosting the current Blackhole implementation delivering the Java 0day. These sites include weather sites, news sites, and of course, adult sites. A few obfuscated files are being delivered to victim systems with names like Stretch.jar, Edit.jar, UTTER-OFFEND.JAR, and more................
https://www.securelist.com/en/blog/208194070/Java_0day_Mass_Exploit_Distribution
-
:AAC
This release contains fixes for security vulnerabilities. For more information, see Oracle Security Alert for CVE-2013-0422 (http://www.oracle.com/technetwork/topics/security/alert-cve-2013-0422-1896849.html)
http://www.oracle.com/technetwork/java/javase/7u11-relnotes-1896856.html