Oracle patches decade-old 'Mark-of-the-Beast' bug in Java
Order restored to universe
Posted in Enterprise Security, 9th February 2011 20:29 GMT
Free whitepaper – Ensuring service assurance in the new normal
Oracle has squashed a decade-old bug in its Java programming framework that allows attackers to bring down sensitive servers by feeding them numerical values with large numbers of decimal places.
The vulnerability in the latest version of Java was disclosed last month and reported by The Reg on Monday. The bug, which stems from the difficulty of representing some floating-point numbers in the binary format, made it possible to carry out denial-of-service attacks when Java applications process the value 2.2250738585072012e-308.
On Tuesday, Oracle patched the Mark-of-the-Beast bug in its Java Runtime Environment. “Java based application and web servers are especially at risk from this vulnerability,” an advisory issued by the company warned.
According to numerous online forums, including this one for Java developers, the bug was first reported in 2001 to Sun Microsystems, which was at the time the official steward of the Java environment. For some reason, the link to the original report was removed last week with no explanation.
The vulnerability was reported again in 2009, but remained unfixed until now. ®

Risk and Resilience
The Register Guide to managing spam
The Impact of IT Security Attitudes
The Register Green Computing Report
The Evolving Security Landscape
