LandzDown Forum

Security => Security Alerts & Briefings => Topic started by: Corrine on January 17, 2017, 11:57:08 PM

Title: Oracle Java Critical Security Update Relased
Post by: Corrine on January 17, 2017, 11:57:08 PM
Oracle released the scheduled critical security updates for its Java SE Runtime Environment software.

The update contains seventeen (17) new security fixes for Oracle Java  SE.  Sixteen (16) of these  vulnerabilities may be remotely exploitable  without authentication,  i.e., may be exploited over a network without  requiring user  credentials. 

Details for the CVE's addressed in the update are available here (http://www.oracle.com/technetwork/security-advisory/cpujan2017verbose-2881728.html#JAVA).

Known Issue: Java Installation will fail for non-admin users with UAC off:

The Java installation on Windows will fail without warning or prompting,   for non-admin users with User Access Control (UAC) disabled. The   installer will leave a directory, [FONT=&amp]jds[/FONT]<number>[FONT=&amp].tmp[/FONT], in the %TEMP% directory.
JDK-8161460 (not public)

Update

If Java is still installed on your computer, it is recommended that this  update be applied as soon as possible due to the threat posed by a  successful attack.

Download Information

Download link:  Java SE 8u121 (http://java.com/en/download/)
Verify your version:  http://www.java.com/en/download/testjava.jsp (http://www.java.com/en/download/testjava.jsp)

Java SE 8u121 Update Release Notes (http://www.oracle.com/technetwork/java/javase/8u121-relnotes-3315208.html)