Oracle releases patch for Java after U.S. government warning


Oracle company logo is shown at the headquarters of Oracle Corporation in Redwood City, California in this February 2, 2010 file photograph. (ROBERT GALBRAITH/REUTERS)

Oracle said Sunday that it has released a patch for its Java software after a bug in the program opened users to malicious hacking.

Security researchers first drew attention to the vulnerability last week, and the U.S. Department of Homeland Security told its employees to disable the software temporarily in Web browsers.

Cybersecurity experts encouraged consumers to download the patch immediately, but some also continued to raise questions about Java’s security since the program has had numerous problems in recent months. And the fixes Oracle released, experts said, may not go deep enough.

“Note that the vulnerabilities Oracle just patched don’t apply to standalone Java applications or server-side Java installs. They apply only to applets, which run inside your browser,” wrote Sophos security researcher Paul Ducklin in a blog post Sunday.

Ideally, he said, users should disable Java altogether if they don’t need it. He also suggested that users could run one browser with Java enabled and one without.

Different browsers have different processes to remove and disable Java, and Sophos has explanations for Firefox, Safari, Chrome, Internet Explorer and Opera.

In Safari, Chrome, Firefox and Opera, users can head to their list of plug-ins and uncheck the mark next to Java to disable the program for as long as they want. In Safari, the option is in a users’ “Security” menu. In Firefox, it’s in the “Tools” menu; Chrome users should type “chrome://plugins” into their menu bar to get to the menu.

When it comes to Internet Explorer, users’ easiest option is to head to the Java Control Panel, which you can launch from the Java applet in the Control Panel. Once there, you can disable the program by unchecking a box in the security tab that says “Enable Java content in browser.”

To take the most drastic measures and remove the program altogether on a PC, users can head to the “Add/Remove” programs list menu in the control panels of Windows computers and delete Java from the Program list.

Related stories:

Oracle says Java flaw, which Homeland Security warned about, will be fixed ‘shortly’

Oracle patches critical hole in Java

Banks seek NSA help amid attacks on their computer systems

Sign up today to receive #thecircuit, a daily roundup of the latest tech policy news from Washington and how it is shaping business, entertainment and science.

Hayley Tsukayama covers consumer technology for The Washington Post.

business

technology

Success! Check your inbox for details. You might also like:

Please enter a valid email address

See all newsletters

Comments
Show Comments
Most Read Business

business

technology

Success! Check your inbox for details.

See all newsletters

To keep reading, please enter your email address.

You’ll also receive from The Washington Post:
  • A free 6-week digital subscription
  • Our daily newsletter in your inbox

Please enter a valid email address

I have read and agree to the Terms of Service and Privacy Policy.

Please indicate agreement.

Thank you.

Check your inbox. We’ve sent an email explaining how to set up an account and activate your free digital subscription.