Java Development Toolkit issues with Firefox



The “Java Deployment Toolkit” that is highlighted in the list of plugins is part of Java and is an insecure version. It’s been blocklisted. See:

Java Deployment Toolkit, versions and older. Reason: security vulnerabilities (see bug 558584).

According to Secunia Advisory SA39260 you should update to Java 6 Update 20 to resolve the issue. Note that, according to US-Cert Vulnerability Note VU#886582 updating to Java 6 Update 20 may still leave you vulnerable to the exploit in some cases. After updating Java you should search for and remove any remaining copies of “npdeploytk.dll” (or rename to “Xnpdeploytk.dll”, which is what I did). See this forum topic for more information:
Your list of plugins shows an outdated Java 5 Update 22 plugin. You should make sure to uninstall older Java versions and remove any outdated Java files in your Program Files\Mozilla Firefox\plugins folder. See if you need help updating or uninstalling Java. For help with other plugins, read and go through the related articles here

In other words, after updating to Java 6 Update 20, the C:\Program Files\Mozilla Firefox\plugins folder should have included an updated and enabled Java Deployment Toolkit plugin named npdeployJava1.dll and the old npdeploytk.dll file should have been gone from that location (it was for me). If an old npdeploytk.dll plugin remained there (or in the “C:\Program Files\Java\jre6\bin\new_plugin\” folder) then it would still show up in the Tools -> Add-ons -> Plugins list as “Java Deployment Toolkit” with the old version number but it should be disabled by the blocklist. If the OLD version is still enabled it should be manually disabled. If you want to get the OLD version of the Java Deployment Toolkit out of the Plugins list you can delete all copies of the file npdeploytk.dll from your system (or rename to Xnpdeploytk.dll ).


Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )


Connecting to %s