Results 1 to 16 of 16

Thread: Unpatched Java 7 Vulnerability

  1. #1

    Default Unpatched Java 7 Vulnerability

    Just a heads up, for those who are jumping on the Java 7 bandwagon:

    The latest Java 7 (and probably all Java 7 releases up to it) has a pretty serious flaw [1] that allows a malicious Java applet to take over your computer. This type of attack is usually done via a malicious website or malicious advertisement served on an otherwise legitimate website.

    Fortunately, this means that you can protect yourself from the most common attack vectors by disabling your browser's Java plugin, or restricting the applets it loads to the bare minimum required for site functionality by using an add-on like NoScript. Java 6 may not have this flaw, so running the latest Java 6 (update 34) may also help protect you.

    I advised the rest of the dev team of this issue, so you can expect a more formal statement in regards to how this impacts Istaria. This post is just a heads up, regardless of whether you're using the new launcher or not.

    You can examine your browser's plugins for known security issues at this site:
    https://browsercheck.qualys.com


    Footnotes:
    1. http://web.nvd.nist.gov/view/vuln/de...=CVE-2012-4681
    You can get anything you want in life -- just make a lot of noise and bite the right people.

  2. #2

    Default Re: Unpatched Java 7 Vulnerability

    Thanks much

  3. #3

    Default Re: Unpatched Java 7 Vulnerability

    In an unexpected turn of events, Oracle just released an update with security fixes for Java 7 and Java 6. Go update!

    You should be running one of these:
    Java 1.7 update 7
    Java 1.6 update 35
    You can get anything you want in life -- just make a lot of noise and bite the right people.

  4. #4

    Default Re: Unpatched Java 7 Vulnerability

    IF we run java 7.u7 will Istaria still be working?
    Northwind * Ancient, Crafter, Lairshaper * 100/100/100
    Northpole * Spoiled biped * 100 BTLM, 100 CLRC, 100 RVR, 100 RNGR, 100 MAGE, 100 WIZ, 100 SORC, 100 CONJ, 100 SPRT, 100 DRU, 100 HLR, 100 GRDN, 100 MON, 60 WAR, 44 BRSK/SPRM, 40 CHSW * 100 BLK, 100 OUT, 100 JWL, 100 ARM, 100 WPN, 100 FLE, 100 FIT, 100 MSN, 100 SCH, 87 SPL, 85 GTH, 85 MIN

  5. #5

    Default Re: Unpatched Java 7 Vulnerability

    Quote Originally Posted by Steelclaw View Post
    In an unexpected turn of events, Oracle just released an update with security fixes for Java 7 and Java 6. Go update!

    You should be running one of these:
    Java 1.7 update 7
    Java 1.6 update 35

    Does this mean the patch will be re-applied very shortly?

  6. #6

    Default Re: Unpatched Java 7 Vulnerability

    I think I will wait a bit of time before I redownload java. Better to be safe than sorry.

  7. #7

    Default Re: Unpatched Java 7 Vulnerability

    This is frustrating. Without the java update, I cannot play Minecraft. WITH the java update, I cannot play Istaria.

    This game.
    Hates.
    Me.
    So much.

    Just one problem after another -.-

    Vamalchior

  8. #8

    Default Re: Unpatched Java 7 Vulnerability

    Quote Originally Posted by Kryodrache View Post
    WITH the java update, I cannot play Istaria.

    Huh? I have no problems with the new launcher and Java 7 update 7. (Which, btw, re-introduced some previously fixed, unreleased vulnerabilities... just can't win.)

    What issues are you having?
    You can get anything you want in life -- just make a lot of noise and bite the right people.

  9. #9

    Default Re: Unpatched Java 7 Vulnerability

    Well, basically, the launcher refuses to work for me with Java 7. I first noticed it when it was unable to update... so I looked into it, said it couldn't find a .jav file... so I uninstalled 7, and it worked.

    Vamalchior

  10. #10

    Default Re: Unpatched Java 7 Vulnerability

    The Java 7 update 7 still has some unpatched 0-days, stick with 1.6 update 35 for now.

  11. #11

    Default Re: Unpatched Java 7 Vulnerability

    Java 1.6u35 sounds like a good bet, yes, though installing it is more trouble than I'm willing to go through. I just gave up for now, and disabled the Java browser plugin.

    Regarding Kryodrache's trouble, assuming you're using the launcher from JavaLauncherII.jar, I suspect that you had a botched Java deployment.
    You can get anything you want in life -- just make a lot of noise and bite the right people.

  12. #12

    Default Re: Unpatched Java 7 Vulnerability

    Any clue as to when this game will be able to run on Java 7 update 7?

  13. #13

    Default Re: Unpatched Java 7 Vulnerability

    FYI Java 7 Update 9, and Java 6 Update 37 are out now.

    Java 7 http://www.java.com/en/download/manual.jsp

    Java 6 http://www.java.com/en/download/manual_v6.jsp

  14. #14

    Default Re: Unpatched Java 7 Vulnerability

    Quote Originally Posted by Guaran View Post
    FYI Java 7 Update 9, and Java 6 Update 37 are out now.

    Java 7 http://www.java.com/en/download/manual.jsp

    Java 6 http://www.java.com/en/download/manual_v6.jsp

    Does Istaria run on these new updates?

  15. #15

    Default Re: Unpatched Java 7 Vulnerability

    I'm at work, so I haven't tried them. Give them a try, more likely than not they will work.

    In any event you want these applied since they protect your pc from java based malware.

    These updates would only affect the java launcher (jlauncher.exe). The old launcher will work regardless (Launcher.exe).

    File names from memory someone correct me if I spelled one wrong.

  16. #16
    Member
    Join Date
    Apr 2005
    Location
    Pacific NW, USA // Order
    Posts
    1,131

    Default Re: Unpatched Java 7 Vulnerability

    Java 7 Rev 9 is working fine for me.

    Knossos

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •