(Yet another) Critical Java Patch Update Java SE 7u13 [View all]
http://www.bleepingcomputer.com/forums/topic483878.html/page__view__findpost__p__2965020
Oracle just released the [url=
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html]February 2013 Critical Patch Update for Java SE.[/url] The original Critical Patch Update for Java SE was scheduled on February 19th, but Oracle decided to accelerate the release of this Critical Patch Update because active exploitation in the wild of one of the vulnerabilities affecting the Java Runtime Environment (JRE) in desktop browsers, was addressed with this Critical Patch Update.
In addition to a number of security in-depth fixes, the February 2013 Critical Patch Update for Java SE contains fixes for 50 security vulnerabilities. 44 of these vulnerabilities only affect client deployment of Java (e.g., Java in Internet browsers). In other words, these vulnerabilities can only be exploited on desktops through Java Web Start applications or Java applets. In addition, one vulnerability affects the installation process of client deployment of Java (i.e. installation of the Java Runtime Environment on desktops). Note also that this Critical Patch Update includes the fixes that were previously released through Security Alert CVE-2013-0422.
snip-
For more information:
The advisory for the February 2013 Critical Patch Update
[url=http://]
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html[/url]
More information about setting the security level in the Java client
[url=http://]
http://docs.oracle.com/javase/7/docs/technotes/guides/jweb/client-security.html[/url]
More information about Oracle Software Security Assurance
[url=http://]
http://www.oracle.com/us/support/assurance/index.html[/url]