Java for Mac OS X 10.4, Release 6 Now Available
December 13th, 2007
Apple has released Java for Mac OS X 10.4, Release 6. Get it here or run "Software Update".
Mac users have not had a Java update since 23 February 2007. That version of Java is reportedly vulnerable to all of the critical exploits that have been announced and fixed by Sun since then.
A quick examination of the "SocketPermission" class indicates that the Sun fixes for preventing DNS rebinding attacks have been included. So, if for no other reason, that makes this an important update. More testing will be needed to see if the fixes were actually effective.
Posted by gfleischer on 2007/12/13 at 23:17 in Security