Thread hijack

I have across a issue with Arduino 1.8.4, the Java application that is been used here in version 5.1. Kaspersky Total Security has come across the issue with Java version 5.1 see below.

KLA11122
Multiple vulnerabilities in Oracle Java SE, Java SE Embedded and JRockit.
Has been detected on the 10/16/2017, Serverty is Critical.
Multiple serious vulnerabilities have been found in Oracle Java SE. Malicious users can exploit these vulnerabilities to cause denial of service and bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. An unspecified vulnerability in subcomponent Smart Card IO can be exploited remotely by unauthenticated attacker via multiple protocols to obtain sensitive information and to bypass security restrictions;
  2. An unspecified vulnerability in subcomponent Serialization can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  3. An unspecified vulnerability in subcomponent RMI (Remote Method Invocation) can be exploited remotely by unauthenticated attacker via multiple protocols to bypass security restrictions;
  4. An unspecified vulnerability in subcomponent Javadoc can be exploited remotely by unauthenticated attacker via multiple protocols to execute arbitrary code;
  5. An unspecified vulnerability in subcomponent Networking can be exploited remotely by unauthenticated attacker via HTTP to cause bypass security restrictions;
  6. An unspecified vulnerability in subcomponent Deployment can be exploited remotely by unauthenticated attacker via multiple protocols to bypass security restrictions;
  7. Unspecified vulnerabilities in subcomponent Server can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service or to bypass security restrictions;
  8. An unspecified vulnerability in subcomponent Server can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  9. An unspecified vulnerability in subcomponent Serialization can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  10. An unspecified vulnerability in subcomponent Hotspot can be exploited remotely by unauthenticated attacker via multiple protocols to bypass security restrictions;
  11. An unspecified vulnerability in subcomponent Serialization can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  12. An unspecified vulnerability in subcomponent Libraries can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  13. An unspecified vulnerability in subcomponent JAXP (Java API for XML Processing) can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  14. An unspecified vulnerability in subcomponent JAX-WS (The Java API for XML Web Services) can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  15. An unspecified vulnerability in subcomponent Networking can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  16. An unspecified vulnerability in subcomponent Security can be exploited remotely by unauthenticated attacker via multiple protocols to bypass security restrictions;
  17. An unspecified vulnerability in subcomponent Serialization can be exploited remotely by unauthenticated attacker via multiple protocols to cause denial of service;
  18. Unspecified vulnerabilities in subcomponent Server can be exploited remotely by unauthenticated attacker via HTTP protocols to bypass security restrictions;
  19. An unspecified vulnerability in subcomponent Libraries can be exploited remotely by unauthenticated attacker via multiple protocols to bypass security restrictions;

Technical details
Vulnerabilities (1), (4) and (6) are related to Java SE.
Vulnerabilities (2), (5), (9), (15) and (16) are related to Java SE, Java SE Embedded and JRockit
Vulnerabilities (3), (10), (12), (13), (14), (17) and (19) are related to Java SE and Java SE Embedded.
Vulnerabilities (7), (8) and (18) are related to Java Management Console.
Vulnerability (11) is related to Java SE and JRockit.

Affected products
Java SE 6 versions earlier than 6u161
Java SE 7 versions earlier than 7u151
Java SE 8 versions earlier than 8u144
Java SE Embedded versions earlier than 8u144
Java SE version 9
JRockit R28.3.15

Solution
Update to the latest version Software downloads Original advisories

Oracle Critical Patch Update Advisory – October 2017

Related products
Oracle JRockit
Oracle Java JRE 1.8.x
Oracle Java JRE 1.7.x
Oracle Java JDK 1.8.x
Oracle Java JDK 1.7.x


Will Java be updated to a latest version for Arduino each time a issue is discovered!


Loizos:
I have across a issue with Arduino 1.8.4, the Java application that is been used here in version 5.1. Kaspersky Total Security has come across the issue with Java version 5.1 see below.

How is this in any way related to a question about whether the Arduino Starter Kit comes with a free subscription to the Chrome App? Answer: It's not. Please don't hijack threads Loizos.

As to your question. The only thing I've heard about Arduino plans is this:

We are not planning any switch to Java9 in the upcoming months

Loizos:
I have across a issue with Arduino 1.8.4

It's ironic that you're concerned about when Arduino will update to a new version of Java but you're using an outdated version of the Arduino IDE.