Feeds

Oracle patches decade-old 'Mark-of-the-Beast' bug in Java

Order restored to universe

Beginner's guide to SSL certificates

Oracle has squashed a decade-old bug in its Java programming framework that allows attackers to bring down sensitive servers by feeding them numerical values with large numbers of decimal places.

The vulnerability in the latest version of Java was disclosed last month and reported by The Reg on Monday. The bug, which stems from the difficulty of representing some floating-point numbers in the binary format, made it possible to carry out denial-of-service attacks when Java applications process the value 2.2250738585072012e-308.

On Tuesday, Oracle patched the Mark-of-the-Beast bug in its Java Runtime Environment. “Java based application and web servers are especially at risk from this vulnerability,” an advisory issued by the company warned.

According to numerous online forums, including this one for Java developers, the bug was first reported in 2001 to Sun Microsystems, which was at the time the official steward of the Java environment. For some reason, the link to the original report was removed last week with no explanation.

The vulnerability was reported again in 2009, but remained unfixed until now. ®

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
BlackEnergy crimeware coursing through US control systems
US CERT says three flavours of control kit are under attack
China is ALREADY spying on Apple iCloud users, claims watchdog
Attack harvests users' info at iPhone 6 launch
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
Getting ahead of the compliance curve
Learn about new services that make it easy to discover and manage certificates across the enterprise and how to get ahead of the compliance curve.