<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New Java Vulnerability Being Exploited in the Wild</title>
	<atom:link href="http://blogs.cisco.com/security/new-java-vulnerability-being-exploited-in-the-wild/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.cisco.com/security/new-java-vulnerability-being-exploited-in-the-wild/</link>
	<description></description>
	<lastBuildDate>Thu, 23 May 2013 13:00:27 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: Omar Santos</title>
		<link>http://blogs.cisco.com/security/new-java-vulnerability-being-exploited-in-the-wild/#comment-697869</link>
		<dc:creator>Omar Santos</dc:creator>
		<pubDate>Mon, 14 Jan 2013 13:40:58 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cisco.com/?p=97371#comment-697869</guid>
		<description><![CDATA[Quick update: Oracle released a software update that fixes this vulnerability. The update is available on their website. If you disabled Java in the Java Control Panel, it will need to be manually re-enable it after installing the patch by using the check box in the Security tab of the Java Control Panel. I have updated the post with the appropriate links.]]></description>
		<content:encoded><![CDATA[<p>Quick update: Oracle released a software update that fixes this vulnerability. The update is available on their website. If you disabled Java in the Java Control Panel, it will need to be manually re-enable it after installing the patch by using the check box in the Security tab of the Java Control Panel. I have updated the post with the appropriate links.
<p class="comment-like"><img class="comment-like-btn" title="Vote" onclick="cl_like_this('http://blogs.cisco.com/wp-admin/admin-ajax.php',697869)" src="http://blogs.cisco.com/wp-content/plugins/comments-likes/images/like.png" />&nbsp;&nbsp;&nbsp;<span id="comment-like-cnt-697869">1</span> like</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jack Wei</title>
		<link>http://blogs.cisco.com/security/new-java-vulnerability-being-exploited-in-the-wild/#comment-697860</link>
		<dc:creator>Jack Wei</dc:creator>
		<pubDate>Sun, 13 Jan 2013 06:14:46 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cisco.com/?p=97371#comment-697860</guid>
		<description><![CDATA[Because a fix is not currently available, users are strongly advised to disable Java and the Java plug-in in web browsers.]]></description>
		<content:encoded><![CDATA[<p>Because a fix is not currently available, users are strongly advised to disable Java and the Java plug-in in web browsers.
<p class="comment-like"><img class="comment-like-btn" title="Vote" onclick="cl_like_this('http://blogs.cisco.com/wp-admin/admin-ajax.php',697860)" src="http://blogs.cisco.com/wp-content/plugins/comments-likes/images/like.png" />&nbsp;&nbsp;&nbsp;<span id="comment-like-cnt-697860">0</span> likes</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Shepard</title>
		<link>http://blogs.cisco.com/security/new-java-vulnerability-being-exploited-in-the-wild/#comment-697859</link>
		<dc:creator>Chris Shepard</dc:creator>
		<pubDate>Sat, 12 Jan 2013 20:20:13 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cisco.com/?p=97371#comment-697859</guid>
		<description><![CDATA[Glad to see it&#039;s just the web plugin that is vulnerable.  I still haven&#039;t found anything that is hitting 1.6 update 36 or 37.  Ideally, people should just stop clicking through things that they didn&#039;t ask for.  We both know that will never happen.]]></description>
		<content:encoded><![CDATA[<p>Glad to see it&#8217;s just the web plugin that is vulnerable.  I still haven&#8217;t found anything that is hitting 1.6 update 36 or 37.  Ideally, people should just stop clicking through things that they didn&#8217;t ask for.  We both know that will never happen.
<p class="comment-like"><img class="comment-like-btn" title="Vote" onclick="cl_like_this('http://blogs.cisco.com/wp-admin/admin-ajax.php',697859)" src="http://blogs.cisco.com/wp-content/plugins/comments-likes/images/like.png" />&nbsp;&nbsp;&nbsp;<span id="comment-like-cnt-697859">1</span> like</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Omar Santos</title>
		<link>http://blogs.cisco.com/security/new-java-vulnerability-being-exploited-in-the-wild/#comment-697857</link>
		<dc:creator>Omar Santos</dc:creator>
		<pubDate>Sat, 12 Jan 2013 20:04:34 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cisco.com/?p=97371#comment-697857</guid>
		<description><![CDATA[Hi Chris, thank you for your comment! You have a very good point! This vulnerability is limited to JDK7. All other releases of Java are not affected. However, there are other vulnerabilities in those earlier versions of code that can also have serious implications. One additional note is that this vulnerability does not affect Java applications directly installed and running on servers, desktops, laptops, phones, and other devices. It only affects the browser plug-ins. Therefore, this is why many are recommending disabling Java in web browsers.]]></description>
		<content:encoded><![CDATA[<p>Hi Chris, thank you for your comment! You have a very good point! This vulnerability is limited to JDK7. All other releases of Java are not affected. However, there are other vulnerabilities in those earlier versions of code that can also have serious implications. One additional note is that this vulnerability does not affect Java applications directly installed and running on servers, desktops, laptops, phones, and other devices. It only affects the browser plug-ins. Therefore, this is why many are recommending disabling Java in web browsers.
<p class="comment-like"><img class="comment-like-btn" title="Vote" onclick="cl_like_this('http://blogs.cisco.com/wp-admin/admin-ajax.php',697857)" src="http://blogs.cisco.com/wp-content/plugins/comments-likes/images/like.png" />&nbsp;&nbsp;&nbsp;<span id="comment-like-cnt-697857">1</span> like</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Shepard</title>
		<link>http://blogs.cisco.com/security/new-java-vulnerability-being-exploited-in-the-wild/#comment-697856</link>
		<dc:creator>Chris Shepard</dc:creator>
		<pubDate>Sat, 12 Jan 2013 18:59:52 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cisco.com/?p=97371#comment-697856</guid>
		<description><![CDATA[Looking through the CVE page it doesn&#039;t appear to affect 1.6.036+.  However, all versions of 1.7 are.  Can we confirm this?  I didn&#039;t update to 1.7 because there were known vulnerabilities in it when it asked me to update but couldn&#039;t find anything in 1.6.035(that I was on at the time).  It&#039;s worth looking at if they or people individually could just re-mediate to 1.6.037 and still maintain full functionality of Java.]]></description>
		<content:encoded><![CDATA[<p>Looking through the CVE page it doesn&#8217;t appear to affect 1.6.036+.  However, all versions of 1.7 are.  Can we confirm this?  I didn&#8217;t update to 1.7 because there were known vulnerabilities in it when it asked me to update but couldn&#8217;t find anything in 1.6.035(that I was on at the time).  It&#8217;s worth looking at if they or people individually could just re-mediate to 1.6.037 and still maintain full functionality of Java.
<p class="comment-like"><img class="comment-like-btn" title="Vote" onclick="cl_like_this('http://blogs.cisco.com/wp-admin/admin-ajax.php',697856)" src="http://blogs.cisco.com/wp-content/plugins/comments-likes/images/like.png" />&nbsp;&nbsp;&nbsp;<span id="comment-like-cnt-697856">1</span> like</p>
]]></content:encoded>
	</item>
</channel>
</rss>
