CVE-2016-0603
published 2016-02-08CVE-2016-0603: Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95, 8u71, and 8u72, when running on Windows, allows remote attackers to affect…
PriorityP341high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
4.07%
89.6th percentile
Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95, 8u71, and 8u72, when running on Windows, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install. NOTE: the previous information is from Oracle's Security Alert for CVE-2016-0603. Oracle has not commented on third-party claims that this is an untrusted search path issue that allows local users to gain privileges via a Trojan horse dll in the "application directory."
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_debian7.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-0603: openjdk-8 - Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95...
vendor_debian·2016·CVSS 7.6
CVE-2016-0603 [HIGH] CVE-2016-0603: openjdk-8 - Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95...
Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95, 8u71, and 8u72, when running on Windows, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install. NOTE: the previous information is from Oracle's Security Alert for CVE-2016-0603. Oracle has not commented on third-party claims that this is an untrusted search path issue that allows local users to gain privileges via a Trojan horse dll in the "application directory."
Scope: local
sid: resolved
GHSA
GHSA-2hfm-pcvh-xc2h: Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95, 8u71, and 8u72, when running on Windows, allows remote attackers to
ghsa_unreviewed·2022-05-13·CVSS 7.6
CVE-2016-0603 [HIGH] GHSA-2hfm-pcvh-xc2h: Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95, 8u71, and 8u72, when running on Windows, allows remote attackers to
Unspecified vulnerability in the Java SE component in Oracle Java SE 6u111, 7u95, 8u71, and 8u72, when running on Windows, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Install. NOTE: the previous information is from Oracle's Security Alert for CVE-2016-0603. Oracle has not commented on third-party claims that this is an untrusted search path issue that allows local users to gain privileges via a Trojan horse dll in the "application directory."
No detection rules found.
No public exploits indexed.
Qualys
Newest Java Addresses Binary Planting Vulnerability | Qualys
blogs_qualys·2016-02-08·CVSS 7.6
CVE-2016-0603 [HIGH] Newest Java Addresses Binary Planting Vulnerability | Qualys
Oracle published a new version of Java 8, 7 and 6 to address a vulnerability in the installer. CVE-2016-0603 addresses a flaw where the attacker would seed the system with malicious DLLs that the installer would use instead of the DLLs included in the package itself. This type of vulnerability is generally known as binary planting .
As Oracle points out existing installations are not at risk. New installations should use the latest fixed packages to address the case where an end user might have visited a malicious site which could have prepared the machine for the attack by downloading altered versions of one of the DLLs involved. Fixed versions of Java are 6 update 113, 7 update 97 and 8 update 73.
Qualys
Newest Java Addresses Binary Planting Vulnerability | Qualys
blogs_qualys·2016-02-08·CVSS 7.6
CVE-2016-0603 [HIGH] Newest Java Addresses Binary Planting Vulnerability | Qualys
Oracle published a new version of Java 8, 7 and 6 to address a vulnerability in the installer. CVE-2016-0603 addresses a flaw where the attacker would seed the system with malicious DLLs that the installer would use instead of the DLLs included in the package itself. This type of vulnerability is generally known as binary planting.
As Oracle points out existing installations are not at risk. New installations should use the latest fixed packages to address the case where an end user might have visited a malicious site which could have prepared the machine for the attack by downloading altered versions of one of the DLLs involved. Fixed versions of Java are 6 update 113, 7 update 97 and 8 update 73.
### Related
http://seclists.org/fulldisclosure/2016/Feb/54http://www.oracle.com/technetwork/topics/security/alert-cve-2016-0603-2874360.htmlhttp://www.securityfocus.com/archive/1/537462/100/0/threadedhttp://www.securityfocus.com/bid/83008http://www.securitytracker.com/id/1034969https://security.gentoo.org/glsa/201610-08https://security.netapp.com/advisory/ntap-20160217-0001/http://seclists.org/fulldisclosure/2016/Feb/54http://www.oracle.com/technetwork/topics/security/alert-cve-2016-0603-2874360.htmlhttp://www.securityfocus.com/archive/1/537462/100/0/threadedhttp://www.securityfocus.com/bid/83008http://www.securitytracker.com/id/1034969https://security.gentoo.org/glsa/201610-08https://security.netapp.com/advisory/ntap-20160217-0001/
2016-02-08
Published