Project

General

Profile

Actions

Bug #165

closed

Oracle Java security risks

Added by Andreas Kuckartz over 11 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
Start date:
03/05/2013
Due date:
% Done:

100%

Estimated time:
(Total: 0.00 h)
Reviewer:
Build Version:

Description

Several organisations including the BSI have today recommended deactivating Java. This is the second time in a few months that this happened due to an unresolved grave Oracle Java security issue.

It is therefore necessary to think about methods to protect Open eCard users and the software against such issues.


Subtasks 1 (0 open1 closed)

Review #173: consider re-implementation as non-Java based versionRejected03/05/2013

Actions
Actions #2

Updated by Andreas Kuckartz over 11 years ago

Following active exploits, Mozilla adds all recent versions of Java to its Firefox add-on blocklist
http://thenextweb.com/apps/2013/01/11/following-active-exploits-mozilla-adds-all-recent-versions-of-java-to-its-firefox-add-on-blocklist/

Actions #3

Updated by Andreas Kuckartz over 11 years ago

CERT does not trust the patched version of Oracle Java which was published on Monday.

"Unless it is absolutely necessary to run Java in web browsers, disable it as described below, even after updating to 7u11. This will help mitigate other Java vulnerabilities that may be discovered in the future."

http://news.cnet.com/8301-1009_3-57563951-83/homeland-security-still-advises-disabling-java-even-after-update/

Actions #4

Updated by Tobias Wich about 11 years ago

  • Target version deleted (4)
Actions #5

Updated by Tobias Wich about 10 years ago

  • Tracker changed from Review to Bug
  • Status changed from New to Closed
  • Target version set to 1.1.0

The use of the Java plugin has been removed in Webstart for the development version. And will be ready for everyone with version 1.1.0.

Actions

Also available in: Atom PDF