Rechercher dans l’assistance

Évitez les escroqueries à l’assistance. Nous ne vous demanderons jamais d’appeler ou d’envoyer un SMS à un numéro de téléphone ou de partager des informations personnelles. Veuillez signaler toute activité suspecte en utilisant l’option « Signaler un abus ».

Learn More

Why is the Java 8.0.25 plugin after 7.0.67 vulnerable too?

  • 6 réponses
  • 12 ont ce problème
  • 1 vue
  • Dernière réponse par the-edmeister

more options

There is very common in the section of the plugins, in the AddOn menu, the message that the java plugin is vulnerable an it is to be used with caution. Now in 8.0.25 again. What does it means? Is there or will be there a solution for that? Is NoScript in this case useful, or another security option?

Thanks!

There is very common in the section of the plugins, in the AddOn menu, the message that the java plugin is vulnerable an it is to be used with caution. Now in 8.0.25 again. What does it means? Is there or will be there a solution for that? Is NoScript in this case useful, or another security option? Thanks!

Solution choisie

It seems that Oracle refuses to fix the vulnerabilities in Java Deployment Toolkit plugin, thus every new version that Oracle releases is marked as vulnerable.

http://www.java.com/en/download/help/firefox_java.xml

https://www.java.com/en/download/faq/deployment_toolkit.xml For the average internet user the Deployment Toolkit isn't needed. Typically it is used by "in house" applications on company intranets that use Oracle software (which tend to use very old versions of Java) and by developers of Java applications.

Lire cette réponse dans son contexte 👍 2

Toutes les réponses (6)

more options

Which Java Plugin are you referring to?

The Java Deployment Toolkit? Or the Java Platform'?

more options

The Java Deployment Toolkit is meant :) It's what Firefox is saying in the plugin section in Addons

Modifié le par hittman

more options

I answered beneath :)

more options

Solution choisie

It seems that Oracle refuses to fix the vulnerabilities in Java Deployment Toolkit plugin, thus every new version that Oracle releases is marked as vulnerable.

http://www.java.com/en/download/help/firefox_java.xml

https://www.java.com/en/download/faq/deployment_toolkit.xml For the average internet user the Deployment Toolkit isn't needed. Typically it is used by "in house" applications on company intranets that use Oracle software (which tend to use very old versions of Java) and by developers of Java applications.

more options

Thanks, so in this case, while I'm not using it - will it be ok to disable it or to change to "Never activate" ? Thanks!

more options

Yes - disabling it is ok.