Download Oracle Java 6.0 Update 35 / 7.0 Update 7

Spread the love

Oracle has released updates to versions 6.0 and 7.0 for both the Java Standard Edition development kit and runtime environment. These updates should include a serious vulnerability in Java 7.0, which was announced earlier this week that it was actively exploited. More information about the security vulnerabilities can be found in the security bulletin below.

Security Alert for CVE-2012-4681 Released

Oracle has just released Security Alert CVE-2012-4681 to address 3 distinct but related vulnerabilities and one security-in-depth issue affecting Java running in desktop browsers. These vulnerabilities are: CVE-2012-4681, CVE-2012-1682, CVE-2012-3136, and CVE-2012-0547. These vulnerabilities are not applicable to standalone Java desktop applications or Java running on servers, ie these vulnerabilities do not affect any Oracle server based software.

Vulnerabilities CVE-2012-4681, CVE-2012-1682, and CVE-2012-3136 have each received a CVSS Base Score of 10.0. This score assumes that the affected users have administrative privileges, as is typical in Windows XP. Vulnerability CVE-20120-0547 has received a CVSS Base Score of 0.0 because this vulnerability is not directly exploitable in typical user deployments, but Oracle has issued a security-in-depth fix for this issue as it can be used in conjunction with other vulnerabilities to significantly increase the overall impact of a successful exploit.

If successfully exploited, these vulnerabilities can provide a malicious attacker the ability to plant discretionary binaries onto the compromised system, eg the vulnerabilities can be exploited to install malware, including Trojans, onto the targeted system. Note that this malware may in some instances be detected by current antivirus signatures upon its installation.

Due to the high severity of these vulnerabilities, Oracle recommends that customers apply this Security Alertas soon as possible. Furthermore, note that the technical details of these vulnerabilities are widely available on the Internet and Oracle has received external reports that these vulnerabilities are being actively exploited in the wild.

  • Developers should download the latest release at
  • Java users should download the latest release of JRE at http://java.comand of course
  • Windows users can take advantage of the Java Automatic Update to get the latest release.

For more information:

  • The Advisory for Security Alert CVE-2012-4681 is located at
  • Users can verify that they’re running the most recent version of Java by visiting:
  • Instructions on removing older (and less secure) versions of Java can be found at

Version number 6.0 update 35 / 7.0 update 7
Release status Final
Operating systems Windows 7, Windows 7 x64, Windows 2000, Linux, Windows XP, macOS, Solaris, Windows Server 2003, Windows XP x64, Windows Server 2003 x64, Linux AMD64, Windows Vista, Windows Vista x64, Windows Server 2008
Website Oracle
Download
License type Conditions (GNU/BSD/etc.)
You might also like
Exit mobile version