Oracle knew about currently exploited Java vulnerabilities for months, researcher says

29.08.2012

"The way in which SunToolkit class and its getField method is used to achieve a complete JVM [Java Virtual Machine] sandbox bypass is different from what we have demonstrated to Oracle," Gowdiak said.

Because of this, the researcher believes that the new exploit is likely the result of someone else independently discovering the same vulnerabilities, rather than a leak of information somewhere in the vulnerability report handling process.

However, nothing can be excluded with 100 percent certainty, Gowdiak said. "We don't know with whom and in what form or detail Oracle is sharing vulnerability information."

According to a status report received on Aug. 23 from Oracle, the company was planning to fix the two vulnerabilities in its October Critical Patch Update (CPU), together with 17 other Java 7 flaws reported by Security Explorations, Gowdiak said.

Oracle releases security patches every four months. The last Java CPU was released in June and only addressed 3 of the security issues reported by Polish security firm.