SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Generic)  >   Oracle Java SE Vendors:   Oracle, Sun
(Oracle Issues Fix for Oracle Linux) Oracle Java SE Multiple Flaws Let Remote and Local Users Gain Elevated Privileges, Remote Users Access and Modify Data, and Remote Users Deny Service
SecurityTracker Alert ID:  1040828
SecurityTracker URL:  http://securitytracker.com/id/1040828
CVE Reference:   CVE-2018-2790, CVE-2018-2794, CVE-2018-2796, CVE-2018-2798, CVE-2018-2814   (Links to External Site)
Date:  May 3 2018
Impact:   Denial of service via network, Disclosure of system information, Disclosure of user information, Modification of system information, Modification of user information, User access via local system, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): Java SE: 6u181, 7u171, 8u162, 10; Java SE Embedded: 8u161; JRockit: R28.3.17
Description:   Multiple vulnerabilities were reported in Oracle Java SE. A remote user can access and modify data on the target system. A remote or local user can gain elevated privileges. A remote user can cause denial of service conditions on the target system.

A remote user can exploit a flaw in the Libraries component to gain elevated privileges [CVE-2018-2825, CVE-2018-2826].

A remote user can exploit a flaw in the Embedded Hotspot component to gain elevated privileges [CVE-2018-2814].

A local user can exploit a flaw in the Install component to gain elevated privileges [CVE-2018-2811].

A local user can exploit a flaw in the JRockit Security component to gain elevated privileges [CVE-2018-2794].

A remote user can exploit a flaw in the JRockit Security component to access and modify data [CVE-2018-2783].

A remote user can exploit a flaw in the JRockit AWT component to cause partial denial of service conditions [CVE-2018-2798].

A remote user can exploit a flaw in the JRockit Concurrency component to cause partial denial of service conditions [CVE-2018-2796].

A remote user can exploit a flaw in the JRockit JAXP component to cause partial denial of service conditions [CVE-2018-2799].

A remote user can exploit a flaw in the JRockit JMX component to cause partial denial of service conditions [CVE-2018-2797].

A remote user can exploit a flaw in the JRockit Security component to cause partial denial of service conditions [CVE-2018-2795].

A remote user can exploit a flaw in the JRockit Serialization component to cause partial denial of service conditions [CVE-2018-2815].

A remote user can exploit a flaw in the JRockit RMI component to partially access and partially modify data [CVE-2018-2800].

A remote user can exploit a flaw in the Embedded Security component to partially modify data [CVE-2018-2790].

XOR19 of Trend Micro's Zero Day Initiative, John Heasman of DocuSign, Francesco Palmarini of Ca' Foscari University of Venice, David Benjamin of Google, Apostolos Giannakidis of Waratek, and Moritz Bechler reported these vulnerabilities.

Impact:   A remote user can obtain data on the target system.

A remote user can modify data on the target system.

A remote user can cause denial of service conditions.

A local user can obtain elevated privileges on the target system.

A remote user can gain elevated privileges on the target system.

Solution:   Oracle has issued a fix for CVE-2018-2790, CVE-2018-2794, CVE-2018-2796, CVE-2018-2798, and CVE-2018-2814 for java-1.7.0-openjdk.

The Oracle Linux advisory is available at:

http://linux.oracle.com/errata/ELSA-2018-1278.html

Vendor URL:  linux.oracle.com/errata/ELSA-2018-1278.html (Links to External Site)
Cause:   Not specified
Underlying OS:  Linux (Oracle)
Underlying OS Comments:  7

Message History:   This archive entry is a follow-up to the message listed below.
Apr 17 2018 Oracle Java SE Multiple Flaws Let Remote and Local Users Gain Elevated Privileges, Remote Users Access and Modify Data, and Remote Users Deny Service



 Source Message Contents

Subject:  [El-errata] ELSA-2018-1278 Important: Oracle Linux 7 java-1.7.0-openjdk security update

Oracle Linux Security Advisory ELSA-2018-1278

http://linux.oracle.com/errata/ELSA-2018-1278.html

The following updated rpms for Oracle Linux 7 have been uploaded to the 
Unbreakable Linux Network:

x86_64:
java-1.7.0-openjdk-1.7.0.181-2.6.14.5.0.1.el7.x86_64.rpm
java-1.7.0-openjdk-accessibility-1.7.0.181-2.6.14.5.0.1.el7.x86_64.rpm
java-1.7.0-openjdk-demo-1.7.0.181-2.6.14.5.0.1.el7.x86_64.rpm
java-1.7.0-openjdk-devel-1.7.0.181-2.6.14.5.0.1.el7.x86_64.rpm
java-1.7.0-openjdk-headless-1.7.0.181-2.6.14.5.0.1.el7.x86_64.rpm
java-1.7.0-openjdk-javadoc-1.7.0.181-2.6.14.5.0.1.el7.noarch.rpm
java-1.7.0-openjdk-src-1.7.0.181-2.6.14.5.0.1.el7.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/java-1.7.0-openjdk-1.7.0.181-2.6.14.5.0.1.el7.src.rpm



Description of changes:

[1:1.7.0.181-2.6.14.5.0.1]
- Update DISTRO_NAME in specfile

[1:1.7.0.181-2.6.14.5]
- added depndence on latest c-j-c who do not have the incorrect jre-abrt 
handling
- Resolves: rhbz#1559766

[1:1.7.0.181-2.6.14.3]
- Bump release number to an unused one as 
rhel-7.5-z-java-unsafe-candidate wrongly using .el7
- Resolves: rhbz#1559766

[1:1.7.0.181-2.6.14.1]
- Fix invalid license 'LGPL+' (should be LGPLv2+ for ECC code) and add 
missing ones
- Resolves: rhbz#1559766

[1:1.7.0.181-2.6.14.0]
- Bump to 2.6.14 and u181b00.
- Drop 8197981 Zero 32-bit patch now applied upstream.
- Update RC4 patch (8076221/PR2809) to apply after 8175075 (disable 3DES)
- Resolves: rhbz#1559766


_______________________________________________
El-errata mailing list
El-errata@oss.oracle.com
https://oss.oracle.com/mailman/listinfo/el-errata
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2021, SecurityGlobal.net LLC