CVE-2016-5542
published 2016-10-25CVE-2016-5542: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to…
PriorityP414low3.1CVSS 3.0
AVNACHPRNUIRSUCNILAN
EPSS
2.79%
84.8th percentile
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to Libraries.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | < openjdk-8 8u111-b14-1 (sid) | openjdk-8 8u111-b14-1 (sid) |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv3.03.1LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv3.1LOW
vendor_debian3.1LOW
vendor_redhat3.1LOW
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gjxp-f524-fgrv: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors re
ghsa_unreviewed·2022-05-13
CVE-2016-5542 [MEDIUM] GHSA-gjxp-f524-fgrv: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors re
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to Libraries.
OSV
openjdk-7 vulnerabilities
osv·2016-11-17·CVSS 3.1
CVE-2016-5542 [LOW] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) packets. An attacker could
use this to send debugging commands to a Java application with debugging
enabled. (CVE-2016-5573)
It was discovered that the Hotspot component of OpenJDK did not properly
check arguments of the Sys
OSV
openjdk-8 vulnerabilities
osv·2016-11-03·CVSS 3.1
CVE-2016-5582 [LOW] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
It was discovered that the Hotspot component of OpenJDK did not properly
check arguments of the System.arraycopy() function in certain cases. An
attacker could use this to bypass Java sandbox restrictions.
(CVE-2016-5582)
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) pa
OSV
CVE-2016-5542: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors re
osv·2016-10-25·CVSS 3.1
CVE-2016-5542 [LOW] CVE-2016-5542: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors re
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to Libraries.
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2016-12-08·CVSS 3.1
CVE-2016-5542 [LOW] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) packets. An attacker could
use this to send debugging commands to a Java application with debugging
enabled. (CVE-2016-5573)
It was discovered that the Hotspo
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2016-11-17·CVSS 3.1
CVE-2016-5542 [LOW] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) packets. An attacker could
use this to send debugging commands to a Java application with debugging
enabled. (CVE-2016-5573)
It was discovered that the Hotspo
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2016-11-03·CVSS 3.1
CVE-2016-5542 [LOW] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
It was discovered that the Hotspot component of OpenJDK did not properly
check arguments of the System.arraycopy() function in certain cases. An
attacker could use this to bypass Java sandbox restrictions.
(CVE-2016-5582)
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK
Red Hat
OpenJDK: missing algorithm restrictions for jar verification (Libraries, 8155973)
vendor_redhat·2016-10-18·CVSS 3.1
CVE-2016-5542 [LOW] CWE-327 OpenJDK: missing algorithm restrictions for jar verification (Libraries, 8155973)
OpenJDK: missing algorithm restrictions for jar verification (Libraries, 8155973)
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to Libraries.
It was discovered that the Libraries component of OpenJDK did not restrict the set of algorithms used for JAR integrity verification. This flaw could allow an attacker to modify content of the JAR file that used weak signing key or hash algorithm.
Debian
CVE-2016-5542: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Emb...
vendor_debian·2016·CVSS 3.1
CVE-2016-5542 [LOW] CVE-2016-5542: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Emb...
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to Libraries.
Scope: local
sid: resolved (fixed in 8u111-b14-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-3539 OpenJDK: MD5 allowed for jar verification (Security, 8171121)
bugzilla·2017-04-18·CVSS 3.1
CVE-2017-3539 [LOW] CVE-2017-3539 OpenJDK: MD5 allowed for jar verification (Security, 8171121)
CVE-2017-3539 OpenJDK: MD5 allowed for jar verification (Security, 8171121)
It was discovered that the Security component of OpenJDK did not allow users to restrict the set of algorithms allowed for Jar integrity verification. This flaw could allow an attacker to modify content of the Jar file that used weak signing key or hash algorithm.
This problem was originally addressed as part of October 2016 CPU as CVE-2016-5542 (bug 1385723). In that update, the following changes were made:
- New security property jdk.jar.disabledAlgorithms was introduced, which can be used to restrict which algorithms can be used for jar verification.
- MD2 hash algorithm and RSA keys with less than 1024 bits were disabled by default.
At the same time, it was announced that the MD5 has algorithm was going to
Bugzilla
CVE-2016-5542 OpenJDK: missing algorithm restrictions for jar verification (Libraries, 8155973)
bugzilla·2016-10-17·CVSS 3.1
CVE-2016-5542 [LOW] CVE-2016-5542 OpenJDK: missing algorithm restrictions for jar verification (Libraries, 8155973)
CVE-2016-5542 OpenJDK: missing algorithm restrictions for jar verification (Libraries, 8155973)
It was discovered that the Libraries component of OpenJDK did not allow users to restrict the set of algorithms allowed for Jar integrity verification. This flaw could allow an attacker to modify content of the Jar file that used weak signing key or hash algorithm.
The fix for this issue adds new security property - jdk.jar.disabledAlgorithms - which defines a set of algorithms not allowed to be used during Jar verification. MD2 hash algorithm and RSA keys with less than 1024 bits are disabled by default. Future updates are also expected to disable MD5 hash algorithm by default.
Discussion:
This change has the following entry in the release notes for Oracle JDK 8u111, 7u121, and 6u131:
http
http://rhn.redhat.com/errata/RHSA-2016-2079.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2088.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2089.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2090.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2136.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2137.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2138.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2658.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2659.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0061.htmlhttp://www.debian.org/security/2016/dsa-3707http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93643http://www.securitytracker.com/id/1037040http://www.ubuntu.com/usn/USN-3130-1http://www.ubuntu.com/usn/USN-3154-1https://access.redhat.com/errata/RHSA-2017:1216https://security.gentoo.org/glsa/201611-04https://security.gentoo.org/glsa/201701-43https://security.netapp.com/advisory/ntap-20161019-0001/http://rhn.redhat.com/errata/RHSA-2016-2079.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2088.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2089.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2090.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2136.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2137.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2138.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2658.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2659.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0061.htmlhttp://www.debian.org/security/2016/dsa-3707http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93643http://www.securitytracker.com/id/1037040http://www.ubuntu.com/usn/USN-3130-1http://www.ubuntu.com/usn/USN-3154-1https://access.redhat.com/errata/RHSA-2017:1216https://security.gentoo.org/glsa/201611-04https://security.gentoo.org/glsa/201701-43https://security.netapp.com/advisory/ntap-20161019-0001/
2016-10-25
Published