Java 7 update 40 released with no announcement

A new version of Java was released yesterday with zero fanfare from Oracle. Presumably that’s because there are no security vulnerability fixes in this release, since normally there would be an announcement on Oracle’s Critical Patch Updates, Security Alerts and Third Party Bulletin blog.

The update is listed on the main release notes page for Java 7. The release notes page for 7u40 shows that there have been a lot of changes in this release, including some related to security, but no fixes for specific security vulnerabilities. The complete list of bugs fixed in this release is enormous.

It will be interesting to see what Adam Gowdiak says about this release, since some of the vulnerabilities he has reported still existed in the previous Java release, 7u25. Update 2013Sep24: According to the vendor log on the Security Explorations site, “Oracle provides a monthly status report for the reported issues. The company informs that Issue 69 is fixed in main codeline and is scheduled for a future CPU.” In other words, Issue 69 is STILL not fixed.

About jrivett

Jeff Rivett has worked with and written about computers since the early 1980s. His first computer was an Apple II+, built by his father and heavily customized. Jeff's writing appeared in Computist Magazine in the 1980s, and he created and sold a game utility (Ultimaker 2, reviewed in the December 1983 Washington Apple Pi Journal) to international markets during the same period. Proceeds from writing, software sales, and contract programming gigs paid his way through university, earning him a Bachelor of Science (Computer Science) degree at UWO. Jeff went on to work as a programmer, sysadmin, and manager in various industries. There's more on the About page, and on the Jeff Rivett Consulting site.

Leave a Reply

Your email address will not be published. Required fields are marked *