Posts

Showing posts with the label Vulnerability

Countermeasures to Neutralize TLS Renegotiation MITM Vulnerability in JAVA

The protocol level TLS renegotiation Man-In-The-Middle (MITM) vulnerability has already been fully fixed in Java SE for quite a while.  The following table shows the status of JDK/JRE releases and updates to neutralize the vulnerability in Java. Renegotiation is Vulnerable Renegotiation is Disabled Renegotiation is Secure JDK/JRE 7 N/A N/A All releases JDK/JRE 6 Update 18 and earlier Updates 19-21 Update 22 JDK/JRE 5.0 Update 23 and earlier Updates 24-25 Update 26 JDK/JRE 1.4.2 Update 25 and earlier Updates 26-27 Update 28 Unfortunately, research shows many famous commercial sites on the Web have not yet upgraded their software, according to the last report, Potential Vulnerability status of major ecommerce sites (Please see my previous post ). Much worse, for some circumstance, it is not always easy to upgrade Java Runtime Environment. In such cases, we need workarounds to mitigate the impact of the vulnerability on vulnerable releases. T he Primary Countermeasu...

TLS Renegotiation MITM Vulnerability is Fully Fixed in Java SE

It's time to upgrade your Java Runtime Environment to JRE 6 update 22, JRE 5.0 update 26, or JRE 1.4.2 update 28 at least , or the latest updates . Sooner, rather than later! Java SE has implemented RFC 5746 , and fully fixed the TLS renegotiation MITM vulnerability from JDK 7 and above update release. Most of the SSL/TLS implementation vendors have already fixed the vulnerability in their product lines. Unfortunately, many famous commercial sites on the Web have not yet upgraded their software, according to the last report (by the edit time of this paper, it is Fri, Jul. 01, 2011) , Potential Vulnerability status of major ecommerce sites . If your site is in list of the above report , it is exposed to public that the site is unsafe. Your site in the risk of attack. Why not take action, right now?