Oracle releases patch for Java after U.S. government warning

ROBERT GALBRAITH/REUTERS - Oracle company logo is shown at the headquarters of Oracle Corporation in Redwood City, California in this February 2, 2010 file photograph.

Oracle said Sunday that it has released a patch for its Java software after a bug in the program opened users to malicious hacking.

Security researchers first drew attention to the vulnerability last week, and the U.S. Department of Homeland Security told its employees to disable the software temporarily in Web browsers.

More tech stories

Real talk about innovations

Real talk about innovations

Just because something is new doesn’t mean it should be touted as an innovation.

Hey Domino’s, stop saying you’re innovative

Hey Domino’s, stop saying you’re innovative

News flash -- replacing a pizza’s crust with breaded chicken breast is not an innovation.

New pressure on Google to crack down on illegal drug sites

New pressure on Google to crack down on illegal drug sites

State attorneys general want the search giant to do more, and some shareholders have filed suit.

Cybersecurity experts encouraged consumers to download the patch immediately, but some also continued to raise questions about Java’s security since the program has had numerous problems in recent months. And the fixes Oracle released, experts said, may not go deep enough.

“Note that the vulnerabilities Oracle just patched don’t apply to standalone Java applications or server-side Java installs. They apply only to applets, which run inside your browser,” wrote Sophos security researcher Paul Ducklin in a blog post Sunday.

Ideally, he said, users should disable Java altogether if they don’t need it. He also suggested that users could run one browser with Java enabled and one without.

Different browsers have different processes to remove and disable Java, and Sophos has explanations for Firefox, Safari, Chrome, Internet Explorer and Opera.

In Safari, Chrome, Firefox and Opera, users can head to their list of plug-ins and uncheck the mark next to Java to disable the program for as long as they want. In Safari, the option is in a users’ “Security” menu. In Firefox, it’s in the “Tools” menu; Chrome users should type “chrome://plugins” into their menu bar to get to the menu.

When it comes to Internet Explorer, users’ easiest option is to head to the Java Control Panel, which you can launch from the Java applet in the Control Panel. Once there, you can disable the program by unchecking a box in the security tab that says “Enable Java content in browser.”

To take the most drastic measures and remove the program altogether on a PC, users can head to the “Add/Remove” programs list menu in the control panels of Windows computers and delete Java from the Program list.

 
Read what others are saying