: Apple releases third Java update to combat Flashback Trojan


CubaMark
Apr 12th, 2012, 04:38 PM
Java for OS X Lion 2012-003 just showed up in my Software Update, but for those looking for the direct download, it hasn't appeared yet on Apple's support site (http://support.apple.com/downloads/) (4:37pm

M.

CubaMark
Apr 12th, 2012, 05:01 PM
Here's the security document:

About Java for OS X Lion 2012-003 (http://support.apple.com/kb/HT5242)

About Java for OS X Lion 2012-003

Summary

This Java security update removes the most common variants of the Flashback malware.

Products Affected
Java, Product Security, OS X Lion, Mac OS X v10.6

This Java security update removes the most common variants of the Flashback malware.

This update also configures the Java web plug-in to disable the automatic execution of Java applets. Users may re-enable automatic execution of Java applets using the Java Preferences application. If the Java web plug-in detects that no applets have been run for an extended period of time it will again disable Java applets.

Java for OS X Lion 2012-003 delivers Java SE 6 version 1.6.0_31 and supersedes all previous versions of Java for OS X Lion.

This update is recommended for all Mac users with Java installed.

Voyager
Apr 12th, 2012, 05:01 PM
I've downloaded the update. I must have clicked on the Software Update link just after it was released. Hopefully there are no bugs or unintended surprises with the update. :D

sch
Apr 12th, 2012, 06:09 PM
I ran the latest update(todays) and no problems so far. However, I do have a question. I have disabled Java in both Firefox and Safari. I opened the Java Pref under "Advance", so what do I un-check to disable the Java applets?

Thanks

pm-r
Apr 12th, 2012, 06:12 PM
The latest "Java for Mac OS X 10.6 Update 8" just became available via my 10.6.8 Software Update at 2:30pm PDT, and it must be a pretty recent release and hot off the press as it wasn't available an hour or so before that time when I checked.


I see in the URL article, and for you Lion users in case you wonder why any java stuff you might need stops working in your browser after the update:

"On Lion only, the update will disable the Java browser and Java Web Start if they haven't been used in 35 days. Users can always reenable them, but the code now won't run by default, preventing users from auto-infecting themselves with any Java-related exploits."

Read more: Apple cures Flashback malware with third OS X Java update | Electronista (http://www.electronista.com/articles/12/04/12/java.for.os.x.2012.003.update.pulls.flashback/#ixzz1rrgvL8Jk)