CVE-2016-0695
published 2016-04-21CVE-2016-0695: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality…
PriorityP434medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
3.40%
87.5th percentile
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related to Security.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | < openjdk-8 8u91-b14-1 (sid) | openjdk-8 8u91-b14-1 (sid) |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jrockit | — | — |
| oracle | linux | — | — |
| oracle | linux | — | — |
| oracle | linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_hpc_node_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv9.6CRITICAL
vendor_ubuntu9.6CRITICAL
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2016-05-10·CVSS 9.6
CVE-2016-0686 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Multiple vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service, expose sensitive data
over the network, or possibly execute arbitrary code. (CVE-2016-0686,
CVE-2016-0687, CVE-2016-3427)
A vulnerability was discovered in the OpenJDK JRE related to information
disclosure. An attacker could exploit this to expose sensitive data over
the network. (CVE-2016-0695)
A vulnerability was discovered in the OpenJDK JRE related to availability.
An attacker could exploit this to cause a denial of service.
(CVE-2016-3425)
Instructions: This update uses a new upstream release, which inc
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2016-05-05·CVSS 9.6
CVE-2016-0686 [CRITICAL] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
Multiple vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service, expose sensitive data
over the network, or possibly execute arbitrary code. (CVE-2016-0686,
CVE-2016-0687, CVE-2016-3427)
Multiple vulnerabilities were discovered in the OpenJDK JRE related
to information disclosure. An attacker could exploit this to expose
sensitive data over the network. (CVE-2016-0695, CVE-2016-3426)
A vulnerability was discovered in the OpenJDK JRE related to availability.
An attacker could exploit this to cause a denial of service.
(CVE-2016-3425)
Instructions: This update uses a new up
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2016-05-05·CVSS 9.6
CVE-2016-0686 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Multiple vulnerabilities were discovered in the OpenJDK JRE related to information
disclosure, data integrity, and availability. An attacker could exploit
these to cause a denial of service, expose sensitive data over the network,
or possibly execute arbitrary code. (CVE-2016-0686, CVE-2016-0687,
CVE-2016-3427)
A vulnerability was discovered in the OpenJDK JRE related to information
disclosure. An attacker could exploit this to expose sensitive data over
the network. (CVE-2016-0695)
A vulnerability was discovered in the OpenJDK JRE related to availability.
An attacker could exploit this to cause a denial of service.
(CVE-2016-3425)
Instructions: This update uses a new upstream release, which inc
Red Hat
OpenJDK: insufficient DSA key parameters checks (Security, 8138593)
vendor_redhat·2016-04-19·CVSS 5.9
CVE-2016-0695 [MEDIUM] OpenJDK: insufficient DSA key parameters checks (Security, 8138593)
OpenJDK: insufficient DSA key parameters checks (Security, 8138593)
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related to Security.
It was discovered that the Security component in OpenJDK failed to check the digest algorithm strength when generating DSA signatures. The use of a digest weaker than the key strength could lead to the generation of signatures that were weaker than expected.
Debian
CVE-2016-0695: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embed...
vendor_debian·2016·CVSS 5.9
CVE-2016-0695 [MEDIUM] CVE-2016-0695: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embed...
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related to Security.
Scope: local
sid: resolved (fixed in 8u91-b14-1)
GHSA
GHSA-5mrp-958f-q2c7: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28
ghsa_unreviewed·2022-05-13
CVE-2016-0695 [MEDIUM] GHSA-5mrp-958f-q2c7: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related to Security.
OSV
openjdk-8 vulnerabilities
osv·2016-05-05·CVSS 9.6
CVE-2016-0686 [CRITICAL] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
Multiple vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity, and availability. An attacker
could exploit these to cause a denial of service, expose sensitive data
over the network, or possibly execute arbitrary code. (CVE-2016-0686,
CVE-2016-0687, CVE-2016-3427)
Multiple vulnerabilities were discovered in the OpenJDK JRE related
to information disclosure. An attacker could exploit this to expose
sensitive data over the network. (CVE-2016-0695, CVE-2016-3426)
A vulnerability was discovered in the OpenJDK JRE related to availability.
An attacker could exploit this to cause a denial of service.
(CVE-2016-3425)
OSV
openjdk-7 vulnerabilities
osv·2016-05-05·CVSS 9.6
CVE-2016-0686 [CRITICAL] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Multiple vulnerabilities were discovered in the OpenJDK JRE related to information
disclosure, data integrity, and availability. An attacker could exploit
these to cause a denial of service, expose sensitive data over the network,
or possibly execute arbitrary code. (CVE-2016-0686, CVE-2016-0687,
CVE-2016-3427)
A vulnerability was discovered in the OpenJDK JRE related to information
disclosure. An attacker could exploit this to expose sensitive data over
the network. (CVE-2016-0695)
A vulnerability was discovered in the OpenJDK JRE related to availability.
An attacker could exploit this to cause a denial of service.
(CVE-2016-3425)
OSV
CVE-2016-0695: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28
osv·2016-04-21·CVSS 5.9
CVE-2016-0695 [MEDIUM] CVE-2016-0695: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related to Security.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2814 Mozilla: Buffer overflow in libstagefright with CENC offsets (MFSA 2016-44)
bugzilla·2016-04-25·CVSS 8.8
CVE-2016-2814 [HIGH] CVE-2016-2814 Mozilla: Buffer overflow in libstagefright with CENC offsets (MFSA 2016-44)
CVE-2016-2814 Mozilla: Buffer overflow in libstagefright with CENC offsets (MFSA 2016-44)
Using Address Sanitizer, security researcher Sascha Just reported a buffer overflow in the libstagefright library due to issues with the handling of CENC offsets and the sizes table. This results in a potentially exploitable crash triggerable through web content.
External Reference:
https://www.mozilla.org/security/announce/2016/mfsa2016-44.html
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Sascha Just
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
Via RHSA-2016:0695 https://rhn.redhat.com/errata/RHSA-2016-0695.html
Bugzilla
CVE-2016-0695 OpenJDK: insufficient DSA key parameters checks (Security, 8138593)
bugzilla·2016-04-18·CVSS 5.9
CVE-2016-0695 [MEDIUM] CVE-2016-0695 OpenJDK: insufficient DSA key parameters checks (Security, 8138593)
CVE-2016-0695 OpenJDK: insufficient DSA key parameters checks (Security, 8138593)
It was discovered that the Security component of OpenJDK failed to properly check DSA (Digital Signature Algorithm) parameters. The use of keys with incorrect parameters could lead to disclosure of sensitive data.
Discussion:
Related note in Oracle JDK release notes:
DSA signature generation is now subject to a key strength check
For signature generation, if the security strength of the digest algorithm
is weaker than the security strength of the key used to sign the signature
(e.g. using (2048, 256)-bit DSA keys with SHA1withDSA signature), the
operation will fail with the error message:
"The security strength of SHA1 digest algorithm is not sufficient for this
key size."
JDK-8138593 (not public)
htt
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00027.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0650.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0651.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0676.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0677.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0678.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0679.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0723.htmlhttp://www.debian.org/security/2016/dsa-3558http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/bid/86438http://www.securitytracker.com/id/1035596http://www.ubuntu.com/usn/USN-2963-1http://www.ubuntu.com/usn/USN-2964-1http://www.ubuntu.com/usn/USN-2972-1https://kc.mcafee.com/corporate/index?page=content&id=SB10159https://security.gentoo.org/glsa/201606-18https://security.netapp.com/advisory/ntap-20160420-0001/http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00022.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00027.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0650.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0651.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0675.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0676.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0677.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0678.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0679.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0723.htmlhttp://www.debian.org/security/2016/dsa-3558http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/bid/86438http://www.securitytracker.com/id/1035596http://www.ubuntu.com/usn/USN-2963-1http://www.ubuntu.com/usn/USN-2964-1http://www.ubuntu.com/usn/USN-2972-1https://kc.mcafee.com/corporate/index?page=content&id=SB10159https://security.gentoo.org/glsa/201606-18https://security.netapp.com/advisory/ntap-20160420-0001/
2016-04-21
Published