CVE-2016-5582
published 2016-10-25CVE-2016-5582: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and…
PriorityP354critical9.6CVSS 3.0
AVNACLPRNUIRSCCHIHAH
EPSS
5.44%
91.8th percentile
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | < openjdk-8 8u111-b14-1 (sid) | openjdk-8 8u111-b14-1 (sid) |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv3.09.6CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.3HIGH
vendor_debian8.3HIGH
vendor_redhat8.3HIGH
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xpxv-6ccf-795w: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
ghsa_unreviewed·2022-05-13·CVSS 9.6
CVE-2016-5573 [CRITICAL] GHSA-xpxv-6ccf-795w: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582.
GHSA
GHSA-f57p-w7p5-298g: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
ghsa_unreviewed·2022-05-13·CVSS 8.3
CVE-2016-5582 [HIGH] CWE-284 GHSA-f57p-w7p5-298g: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.
OSV
openjdk-7 vulnerabilities
osv·2016-11-17·CVSS 3.1
CVE-2016-5542 [LOW] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) packets. An attacker could
use this to send debugging commands to a Java application with debugging
enabled. (CVE-2016-5573)
It was discovered that the Hotspot component of OpenJDK did not properly
check arguments of the Sys
OSV
openjdk-8 vulnerabilities
osv·2016-11-03·CVSS 3.1
CVE-2016-5582 [LOW] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
It was discovered that the Hotspot component of OpenJDK did not properly
check arguments of the System.arraycopy() function in certain cases. An
attacker could use this to bypass Java sandbox restrictions.
(CVE-2016-5582)
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) pa
OSV
CVE-2016-5582: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
osv·2016-10-25·CVSS 8.3
CVE-2016-5582 [HIGH] CVE-2016-5582: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.
OSV
CVE-2016-5573: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
osv·2016-10-25·CVSS 8.3
CVE-2016-5573 [HIGH] CVE-2016-5573: Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integri
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582.
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2016-12-08·CVSS 3.1
CVE-2016-5542 [LOW] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) packets. An attacker could
use this to send debugging commands to a Java application with debugging
enabled. (CVE-2016-5573)
It was discovered that the Hotspo
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2016-11-17·CVSS 3.1
CVE-2016-5542 [LOW] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK did not properly
check received Java Debug Wire Protocol (JDWP) packets. An attacker could
use this to send debugging commands to a Java application with debugging
enabled. (CVE-2016-5573)
It was discovered that the Hotspo
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2016-11-03·CVSS 3.1
CVE-2016-5542 [LOW] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
It was discovered that the Hotspot component of OpenJDK did not properly
check arguments of the System.arraycopy() function in certain cases. An
attacker could use this to bypass Java sandbox restrictions.
(CVE-2016-5582)
It was discovered that OpenJDK did not restrict the set of algorithms used
for Jar integrity verification. An attacker could use this to modify
without detection the content of a JAR file, affecting system integrity.
(CVE-2016-5542)
It was discovered that the JMX component of OpenJDK did not sufficiently
perform classloader consistency checks. An attacker could use this to
bypass Java sandbox restrictions. (CVE-2016-5554)
It was discovered that the Hotspot component of OpenJDK
Red Hat
OpenJDK: insufficient checks of JDWP packets (Hotspot, 8159519)
vendor_redhat·2016-10-18·CVSS 8.3
CVE-2016-5573 [HIGH] CWE-20 OpenJDK: insufficient checks of JDWP packets (Hotspot, 8159519)
OpenJDK: insufficient checks of JDWP packets (Hotspot, 8159519)
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582.
It was discovered that the Hotspot component of OpenJDK did not properly check received Java Debug Wire Protocol (JDWP) packets. An attacker could possibly use this flaw to send debugging commands to a Java program running with debugging enabled if they could make victim's browser send HTTP requests to the JDWP port of the debugged application.
Red Hat
OpenJDK: incomplete type checks of System.arraycopy arguments (Hotspot, 8160591)
vendor_redhat·2016-10-18·CVSS 8.3
CVE-2016-5582 [HIGH] CWE-843 OpenJDK: incomplete type checks of System.arraycopy arguments (Hotspot, 8160591)
OpenJDK: incomplete type checks of System.arraycopy arguments (Hotspot, 8160591)
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.
It was discovered that the Hotspot component of OpenJDK did not properly check arguments of the System.arraycopy() function in certain cases. An untrusted Java application or applet could use this flaw to corrupt virtual machine's memory and completely bypass Java sandbox restrictions.
Debian
CVE-2016-5573: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Emb...
vendor_debian·2016·CVSS 8.3
CVE-2016-5573 [HIGH] CVE-2016-5573: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Emb...
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582.
Scope: local
sid: resolved (fixed in 8u111-b14-1)
Debian
CVE-2016-5582: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Emb...
vendor_debian·2016·CVSS 8.3
CVE-2016-5582 [HIGH] CVE-2016-5582: openjdk-8 - Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Emb...
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.
Scope: local
sid: resolved (fixed in 8u111-b14-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5582 OpenJDK: incomplete type checks of System.arraycopy arguments (Hotspot, 8160591)
bugzilla·2016-10-16·CVSS 9.6
CVE-2016-5582 [CRITICAL] CVE-2016-5582 OpenJDK: incomplete type checks of System.arraycopy arguments (Hotspot, 8160591)
CVE-2016-5582 OpenJDK: incomplete type checks of System.arraycopy arguments (Hotspot, 8160591)
It was discovered that the Hotspot component of OpenJDK did not check types of System.arraycopy() function arguments src and dest in certain cases. An untrusted Java application or applet could use this flaw to corrupt virtual machine's memory and bypass Java sandbox restrictions.
Discussion:
Public now via Oracle CPU October 2016, fixed in Oracle JDK 8u111, 7u121, and 6u131.
External References:
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html#AppendixJAVA
---
OpenJDK 8 upstream commit:
http://hg.openjdk.java.net/jdk8u/jdk8u/hotspot/rev/a3ede966ecfe
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Lin
arXiv
Evaluation of LLM Chatbots for OSINT-based Cyber Threat Awareness
arxiv_fulltext·2024-04-19
Evaluation of LLM Chatbots for OSINT-based Cyber Threat Awareness
1
.001
Fig.\
[mode = title]Evaluation of LLM Chatbots for OSINT-based Cyber Threat Awareness
E-mail addresses: [email protected] (S. Shafee), [email protected] (A. Bessani),
[email protected] (P.M. Ferreira).
blackSamaneh Shafeecorrauth*, Alysson Bessani, Pedro M. Ferreira
[]organization=LASIGE, Faculdade de Ciências, Universidade de Lisboa,
country=Portugal
[1]Corresponding author at: LASIGE, Faculdade de Ciências, Universidade de
Lisboa, Portugal.
corrauthCorresponding author: Samaneh Shafee - [email protected]
## Abstract
Knowledge sharing about emerging threats is crucial in the rapidly advancing field of cybersecurity and forms the foundation of Cyber Threat Intelligence (CTI).
In this context, Large Language Models are becoming increasingly signifi
http://rhn.redhat.com/errata/RHSA-2016-2079.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2088.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2089.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2090.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2658.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0061.htmlhttp://www.debian.org/security/2016/dsa-3707http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93623http://www.securitytracker.com/id/1037040http://www.ubuntu.com/usn/USN-3130-1http://www.ubuntu.com/usn/USN-3154-1https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3Ehttps://security.gentoo.org/glsa/201611-04https://security.gentoo.org/glsa/201701-43https://security.netapp.com/advisory/ntap-20161019-0001/http://rhn.redhat.com/errata/RHSA-2016-2079.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2088.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2089.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2090.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2658.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0061.htmlhttp://www.debian.org/security/2016/dsa-3707http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93623http://www.securitytracker.com/id/1037040http://www.ubuntu.com/usn/USN-3130-1http://www.ubuntu.com/usn/USN-3154-1https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3Ehttps://security.gentoo.org/glsa/201611-04https://security.gentoo.org/glsa/201701-43https://security.netapp.com/advisory/ntap-20161019-0001/
2016-10-25
Published