1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

SunJava Security Hole - Versions 1.4.1-1.4.2_04

Discussion in 'Firefox, Thunderbird & SeaMonkey' started by Ramona, 2004/07/14.

Thread Status:
Not open for further replies.
  1. 2004/07/14
    Ramona

    Ramona Geek Member Alumni Thread Starter

    Joined:
    2001/12/31
    Messages:
    7,481
    Likes Received:
    2
    SunJava Security Vulnerability - Versions 1.4.1-1.4.2_04

    All users should update to JRE 1.4.2_05, as previous versions have a security vulnerability.


    Sun Java Runtime Environment Font Object Assertion Failure Denial Of Service Vulnerability

    published Jun 28, 2004
    updated Jul 14, 2004

    Vulnerable

    Sun JRE (Linux Production Release) 1.4.1 _03
    Sun JRE (Linux Production Release) 1.4.1 _02
    Sun JRE (Linux Production Release) 1.4.1 _01
    + Opera Software Opera Web Browser 7.11
    Sun JRE (Linux Production Release) 1.4.1
    Sun JRE (Linux Production Release) 1.4.2 _04
    Sun JRE (Linux Production Release) 1.4.2 _03
    Sun JRE (Linux Production Release) 1.4.2 _02
    Sun JRE (Linux Production Release) 1.4.2 _01
    Sun JRE (Linux Production Release) 1.4.2
    Sun JRE (Solaris Production Release) 1.4.1 _03
    Sun JRE (Solaris Production Release) 1.4.1 _02
    Sun JRE (Solaris Production Release) 1.4.1 _01
    + Opera Software Opera Web Browser 7.11
    Sun JRE (Solaris Production Release) 1.4.1
    Sun JRE (Solaris Production Release) 1.4.2 _04
    Sun JRE (Solaris Production Release) 1.4.2 _03
    Sun JRE (Solaris Production Release) 1.4.2 _02
    Sun JRE (Solaris Production Release) 1.4.2 _01
    Sun JRE (Solaris Production Release) 1.4.2
    Sun JRE (Windows Production Release) 1.4.1 _07
    Sun JRE (Windows Production Release) 1.4.1 _03
    Sun JRE (Windows Production Release) 1.4.1 _02
    Sun JRE (Windows Production Release) 1.4.1 _01
    + Opera Software Opera Web Browser 7.11
    + Opera Software Opera Web Browser 7.11 j
    Sun JRE (Windows Production Release) 1.4.1
    Sun JRE (Windows Production Release) 1.4.2 _04
    Sun JRE (Windows Production Release) 1.4.2 _03
    Sun JRE (Windows Production Release) 1.4.2 _02
    Sun JRE (Windows Production Release) 1.4.2 _01
    Sun JRE (Windows Production Release) 1.4.2

    Not Vulnerable




    Java(TM) 2 Runtime Environment, Standard Edition 1.4.2_05, Download


    Ramona
     
  2. 2004/07/14
    Christer

    Christer Geek Member Staff

    Joined:
    2002/12/17
    Messages:
    6,566
    Likes Received:
    73
    I just checked Sun's homepage and the latest version for download is 1.4.2_04 which I already have (1.4.2_04-b05 according to "About" in the control panel).

    I tried to update the current installation but the message was that I already have the latest Java Platform installed.

    I'll check back later ...... :confused: ...... !

    Christer

    Edited:

    I am however using I.E.6 ...... :eek: ...... is there a difference ...... :D ...... ?
     
    Last edited: 2004/07/14

  3. to hide this advert.

  4. 2004/07/14
    Dennis L Lifetime Subscription

    Dennis L Inactive Alumni

    Joined:
    2002/06/07
    Messages:
    2,557
    Likes Received:
    2
    Hi Christer

    I came thru this Google link for Sun...
    Java(TM) 2 Runtime Environment, Standard Edition 1.4.2_05, Download page
    Installed a copy on XP and w98.

    UPDATE..............

    Christer
    I am however using I.E.6 ...... ...... is there a difference ...... ...... ?
    During installation, will ask if you want program applied to IE and / or Mozilla 1.1 and higher.
     
    Last edited: 2004/07/14
  5. 2004/07/14
    Christer

    Christer Geek Member Staff

    Joined:
    2002/12/17
    Messages:
    6,566
    Likes Received:
    73
    Hi Dennis!

    Thanks for the link. It will be interesting to see when us mere mortals will get it from the usual webpage!

    Christer

    Edited after Your update:

    I always download the offline installation file to my HDD and it was possible to pick the correct one for Windows at the page to which You linked too.
     
  6. 2004/07/14
    Christer

    Christer Geek Member Staff

    Joined:
    2002/12/17
    Messages:
    6,566
    Likes Received:
    73
    I installed 1.4.2_05 (1.4.2_05-b04 according to "About" in the control panel).

    Either is this information on the new version smoking hot or is the update engine in the Java control panel a bit slow on retrieving information (I run it manually).

    Christer
     
  7. 2004/07/14
    Dennis L Lifetime Subscription

    Dennis L Inactive Alumni

    Joined:
    2002/06/07
    Messages:
    2,557
    Likes Received:
    2
    It will be interesting to see when us mere mortals will get it from the usual webpage!

    My only consolation to the webmaster at Java.com ... he is also a mere mortal.

    Question to anyone out there....
    I have SpyBot / TeaTimer birddogging any changes to the Registry. When installing Java to w98, it asked for an allowed change to Active X settings... but did NOT for XP. Anyone know what changes were made in w98??
     
  8. 2004/07/14
    Ramona

    Ramona Geek Member Alumni Thread Starter

    Joined:
    2001/12/31
    Messages:
    7,481
    Likes Received:
    2
    Christer, et al,

    I changed the link for the download. Sorry you couldn't get there, but it did work when I first opened the thread. I'm sure the site is busy now. At any rate I changed the link to: http://java.sun.com/j2se/1.4.2/download.html
    From this page you can get the J2SE v 1.4.2_05 JRE download.

    Ramona
     
  9. 2004/07/15
    Christer

    Christer Geek Member Staff

    Joined:
    2002/12/17
    Messages:
    6,566
    Likes Received:
    73
    Dennis,
    the webmaster is probably a mere mortal too but I wouldn't have found the download location inside the "developer section" without Your directions.

    Ramona,
    nothing to be sorry about. It was a good catch in the first place!

    My point was (and under the circumstances at this time still is) that people relying on the update function and/or the download page accessed from Sun's main page will not get it.

    Christer
     
  10. 2004/07/15
    SVEN

    SVEN Well-Known Member

    Joined:
    2004/01/02
    Messages:
    862
    Likes Received:
    7
    Do I uninstall the old versions?

    Hi All,
    I finally managed to download Java 1.4.2_05 and installed it without problems.
    Shortly after that I wanted to uninstall a differed program and found that I have 3 java versions installed in Add or remove programs. Do I uninstall the old versions?
    Should I have uninstalled them before I installed the new version?
    Any advice is appreciated
    Sven
     
    SVEN,
    #9
  11. 2004/07/15
    Christer

    Christer Geek Member Staff

    Joined:
    2002/12/17
    Messages:
    6,566
    Likes Received:
    73
    Hi Sven!

    I never checked until You brought my attention to it. I have two versions installed, they both show up in add/remove and in C:\Program\Java but only the latest show up in IE > Tools > Intenet options > Advanced > Java.

    I suppose that the best way would be to uninstall the previous version prior to installing the new version and it's strange that the installer doesn't do it for You.
    I mean, even Symantec uninstall the previous LiveUpdate engine prior to installing the new one ...... :rolleyes: ...... !

    Christer
     
  12. 2004/07/15
    Ramona

    Ramona Geek Member Alumni Thread Starter

    Joined:
    2001/12/31
    Messages:
    7,481
    Likes Received:
    2
    SVEN, and Christer,

    As with most programs, MHO is that it's always better to do a clean install. However, there is nothing in the Install Instructions or Release Notes that indicate you should uninstall before updating. I would definitely uninstall all but Version 1.4.2_05. Remember to reboot after each uninstall, in order for the system to update files.

    Ramona
     
  13. 2004/07/16
    Christer

    Christer Geek Member Staff

    Joined:
    2002/12/17
    Messages:
    6,566
    Likes Received:
    73
    On my system _04 and _05 are in separate folders and it doesn't seem to be an "on top of" installation. I haven't checked the registry, though.

    I will wait until SP2 is released, do some maintenance (restoring a suitable Ghost Image ...... ;) ......) to get to a clean state and take it from there.

    Christer

    Edited:

    I agree that clean installs are the best, I almost never do an update if a clean install is an option. I use Ghost Images to roll back to get rid of applications that come in new versions every now and then. Java is one of those "applications" that were installed last to be easy to get rid of.
     
    Last edited: 2004/07/16
  14. 2004/07/18
    Christer

    Christer Geek Member Staff

    Joined:
    2002/12/17
    Messages:
    6,566
    Likes Received:
    73
    I checked just now and Sun has caught up with Ramona ...... ;) ...... !

    Christer
     
  15. 2004/07/18
    Ramona

    Ramona Geek Member Alumni Thread Starter

    Joined:
    2001/12/31
    Messages:
    7,481
    Likes Received:
    2
    LOL! :D Thanks for the heads up Christer...

    Ramona
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.