RCS Purges Java from Classic Selector

RCS has taken steps to remove the last few remaining pieces of Java from its legacy music scheduler, Selector 15, citing recently stated “zero-day vulnerability” security concerns.

近期業界的相關報導指出,攻擊者可能利用此零日漏洞在目標裝置上執行任意程式碼。因此,攻擊者不僅能入侵該裝置,還能竊取裝置上的任何資料,並將其轉變為「節點」或「殭屍電腦」。.

Although the amount of Java code is only a very small portion of Selector 15, RCS will replace it immediately with a more secure technology. No other RCS products use this technology.

Philippe Generali(RCS 總裁/執行長)表示:「Java 在客戶端桌面上的運作問題已存在一段時間。當我們著手設計 Zetta®、GSelector®、 Aquira® 及 RCS News 等產品時,我們採用了更可靠的技術,這些技術符合客戶應得的資安標準。此舉能立即解決我們舊版排程器中極小部分的問題,而非等待 Java 的修補程式——據部分專家表示,該修補程式可能需要兩年時間才能推出。」“

Generali 補充道:「身為廣播軟體領域的全球領導者,我們有責任提醒客戶注意任何可能導致惡意第三方接管廣播電台的漏洞。」“

More Background Source Material:
Java’s security dilemma: Old, vulnerable versions won’t go away …InfoWorld January 21, 2014
Security experts on Java: Fixing zero-day exploit could take ‘two years’ …ZDNet January 14, 2014
Homeland Security warns to disable Java amid zero-day flaw…ZDNet January 11, 2013