設為首頁收藏本站

艾歐踢論壇

 找回密碼
 立即註冊

QQ登錄

只需一步,快速開始

搜索
熱搜: 活動 交友 discuz
查看: 949|回復: 0
打印 上一主題 下一主題

Security Alert CVE-2016-0603 Released

[複製鏈接]
跳轉到指定樓層
樓主
發表於 2016-2-10 15:27:48 | 只看該作者 回帖獎勵 |倒序瀏覽 |閱讀模式

Oracle just released Security Alert CVE-2016-0603 to address a vulnerability that can be exploited when installing Java 6, 7 or 8 on the Windows platform.

This vulnerability has received a CVSS Base Score of 7.6.


To be successfully exploited, this vulnerability requires that an unsuspecting user be tricked into visiting a malicious web site and download files to the user's system before installing Java 6, 7 or 8. Though considered relatively complex to exploit, this vulnerability may result, if successfully exploited,

in a complete compromise of the unsuspecting user’s system.


Because the exposure exists only during the installation process, users need not upgrade existing Java installations to address the vulnerability.

However, Java users who have downloaded any old version of Java prior to 6u113, 7u97 or 8u73,

should discard these old downloads and replace them with 6u113, 7u97 or 8u73 or later.


As a reminder, Oracle recommends that Java home users visit Java.com to ensure that they are running the most recent version of Java SE and that all older versions of Java SE have been completely removed.

Oracle further advises against downloading Java from sites other than Java.com as these sites may be malicious.


分享到:  QQ好友和群QQ好友和群 QQ空間QQ空間 騰訊微博騰訊微博 騰訊朋友騰訊朋友
收藏收藏 轉播轉播 分享分享 分享淘帖
回復

使用道具 舉報

您需要登錄後才可以回帖 登錄 | 立即註冊

本版積分規則

小黑屋|Archiver|手機版|艾歐踢創新工坊    

GMT+8, 2024-5-16 22:59 , Processed in 0.254996 second(s), 21 queries .

Powered by Discuz! X3.2

© 2001-2013 Comsenz Inc.

快速回復 返回頂部 返回列表