MacOS Users vulnerable to Blackhole exploit kit
by Manuel Humberto Santander Pelaez (Version: 2)
UPDATE: Apple just released Java for OS X 2012-001 and Java for Mac OS X 10.6 Update 7, which addresses this vulnerability. You can download the new versions from http://www.apple.com/support/downloads. More information about the release notes at http://www.oracle.com/technetwork/java/javase/releasenotes-136954.html
If you own a MacOS computer, you might want to disable java for a while until Oracle develops a patch to solve CVE-2012-0507 vulnerability, because there is a Blackhole Exploit Kit version in the wild exploiting this vulnerability and it also can be exploited using metasploit.
If you want to disable java plugins in your MacOS computer, Marcus J. Carey created a video showing how to do it.
More information about this issue at https://www.f-secure.com/weblog/archives/00002341.html
Manuel Humberto Santander Peláez
SANS Internet Storm Center - Handler
Twitter: @manuelsantander
Web:http://manuel.santander.name
e-mail:msantand at isc dot sans dot org
Comments
bartes
Apr 4th 2012
1 decade ago
Dr. J.
Apr 4th 2012
1 decade ago
With your UPDATE post being at the top, I was confused when reading this since I didn't see the original article before you posted the update
Thanks for the great work Handlers!!
K-Dee
Apr 4th 2012
1 decade ago
http://support.apple.com/kb/HT5228 . It does include CVE-2012-0507
Dr. J.
Apr 4th 2012
1 decade ago