CVE-2017-3231
published 2017-01-27CVE-2017-3231: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u131…
PriorityP421medium4.3CVSS 3.0
AVNACLPRNUIRSUCLINAN
EPSS
2.18%
80.4th percentile
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS v3.0 Base Score 4.3 (Confidentiality impacts).
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | < openjdk-8 8u121-b13-1 (sid) | openjdk-8 8u121-b13-1 (sid) |
| oracle | java_se | — | — |
| oracle | java_se | — | — |
| oracle | java_se | — | — |
| oracle | java_se_embedded | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2017-02-16·CVSS 7.5
CVE-2016-2183 [HIGH] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Karthik Bhargavan and Gaetan Leurent discovered that the DES and
Triple DES ciphers were vulnerable to birthday attacks. A remote
attacker could possibly use this flaw to obtain clear text data from
long encrypted sessions. This update moves those algorithms to the
legacy algorithm set and causes them to be used only if no non-legacy
algorithms can be negotiated. (CVE-2016-2183)
It was discovered that OpenJDK accepted ECSDA signatures using
non-canonical DER encoding. An attacker could use this to modify or
expose sensitive data. (CVE-2016-5546)
It was discovered that covert timing channel vulnerabilities existed
in the DSA implementations in OpenJDK. A remote attacker could use
this to expose se
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2017-02-09·CVSS 7.5
CVE-2016-2183 [HIGH] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Karthik Bhargavan and Gaetan Leurent discovered that the DES and
Triple DES ciphers were vulnerable to birthday attacks. A remote
attacker could possibly use this flaw to obtain clear text data from
long encrypted sessions. This update moves those algorithms to the
legacy algorithm set and causes them to be used only if no non-legacy
algorithms can be negotiated. (CVE-2016-2183)
It was discovered that OpenJDK accepted ECSDA signatures using
non-canonical DER encoding. An attacker could use this to modify or
expose sensitive data. (CVE-2016-5546)
It was discovered that OpenJDK did not properly verify object
identifier (OID) length when reading Distinguished Encoding Rules
(DER) records, as used in
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2017-01-25·CVSS 7.5
CVE-2016-2183 [HIGH] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
Karthik Bhargavan and Gaetan Leurent discovered that the DES and
Triple DES ciphers were vulnerable to birthday attacks. A remote
attacker could possibly use this flaw to obtain clear text data from
long encrypted sessions. This update moves those algorithms to the
legacy algorithm set and causes them to be used only if no non-legacy
algorithms can be negotiated. (CVE-2016-2183)
It was discovered that OpenJDK accepted ECSDA signatures using
non-canonical DER encoding. An attacker could use this to modify or
expose sensitive data. (CVE-2016-5546)
It was discovered that OpenJDK did not properly verify object
identifier (OID) length when reading Distinguished Encoding Rules
(DER) records, as used in
Red Hat
OpenJDK: URLClassLoader insufficient access control checks (Networking, 8151934)
vendor_redhat·2017-01-17·CVSS 4.3
CVE-2017-3231 [MEDIUM] OpenJDK: URLClassLoader insufficient access control checks (Networking, 8151934)
OpenJDK: URLClassLoader insufficient access control checks (Networking, 8151934)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applet
Debian
CVE-2017-3231: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subc...
vendor_debian·2017·CVSS 4.3
CVE-2017-3231 [MEDIUM] CVE-2017-3231: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subc...
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and
GHSA
GHSA-25f7-696r-m32w: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking)
ghsa_unreviewed·2022-05-14
CVE-2017-3231 [MEDIUM] CWE-200 GHSA-25f7-696r-m32w: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and
OSV
openjdk-7 vulnerabilities
osv·2017-02-09·CVSS 7.5
CVE-2016-2183 [HIGH] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Karthik Bhargavan and Gaetan Leurent discovered that the DES and
Triple DES ciphers were vulnerable to birthday attacks. A remote
attacker could possibly use this flaw to obtain clear text data from
long encrypted sessions. This update moves those algorithms to the
legacy algorithm set and causes them to be used only if no non-legacy
algorithms can be negotiated. (CVE-2016-2183)
It was discovered that OpenJDK accepted ECSDA signatures using
non-canonical DER encoding. An attacker could use this to modify or
expose sensitive data. (CVE-2016-5546)
It was discovered that OpenJDK did not properly verify object
identifier (OID) length when reading Distinguished Encoding Rules
(DER) records, as used in x.509 certificates and elsewhere. An
attacker could use this to c
OSV
openjdk-8 vulnerabilities
osv·2017-01-25·CVSS 7.5
CVE-2016-2183 [HIGH] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
Karthik Bhargavan and Gaetan Leurent discovered that the DES and
Triple DES ciphers were vulnerable to birthday attacks. A remote
attacker could possibly use this flaw to obtain clear text data from
long encrypted sessions. This update moves those algorithms to the
legacy algorithm set and causes them to be used only if no non-legacy
algorithms can be negotiated. (CVE-2016-2183)
It was discovered that OpenJDK accepted ECSDA signatures using
non-canonical DER encoding. An attacker could use this to modify or
expose sensitive data. (CVE-2016-5546)
It was discovered that OpenJDK did not properly verify object
identifier (OID) length when reading Distinguished Encoding Rules
(DER) records, as used in x.509 certificates and elsewhere. An
attacker could use this to c
OSV
CVE-2017-3231: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking)
osv·2017-01-18·CVSS 4.3
CVE-2017-3231 [MEDIUM] CVE-2017-3231: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3254 thrift: Infinite recursion via vectors involving the skip function
bugzilla·2017-06-19·CVSS 6.5
CVE-2015-3254 [MEDIUM] CVE-2015-3254 thrift: Infinite recursion via vectors involving the skip function
CVE-2015-3254 thrift: Infinite recursion via vectors involving the skip function
The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.
References:
http://grokbase.com/t/thrift/user/15c2tss3td/notice-apache-thrift-security-vulnerability-cve-2015-1774
Upstream issue:
https://issues.apache.org/jira/browse/THRIFT-3231
Upstream patch:
https://github.com/apache/thrift/commit/cfaadcc4adcfde2a8232c62ec89870b73ef40df1
Discussion:
Created thrift tracking bugs for this issue:
Affects: epel-7 [bug 1462785]
Affects: fedora-all [bug 1462784]
---
This issue has been addressed in the following products:
Red Hat JBoss Data Virtualization
Via RHSA-2017:2477 https://acc
Bugzilla
CVE-2017-3231 OpenJDK: URLClassLoader insufficient access control checks (Networking, 8151934)
bugzilla·2017-01-16·CVSS 4.3
CVE-2017-3231 [MEDIUM] CVE-2017-3231 OpenJDK: URLClassLoader insufficient access control checks (Networking, 8151934)
CVE-2017-3231 OpenJDK: URLClassLoader insufficient access control checks (Networking, 8151934)
It was discovered that the URLClassLoader class in the Networking component of OpenJDK did not properly check access control context when downloading class files. An untrusted Java application or applet could use this flaw to make HTTP requests to locations that should not be accessible, bypassing certain Java sandbox restrictions.
Discussion:
Related entry in the Oracle JDK release notes:
http://www.oracle.com/technetwork/java/javase/8u121-relnotes-3315208.html
http://www.oracle.com/technetwork/java/javaseproducts/documentation/javase7supportreleasenotes-1601161.html#R170_131
http://www.oracle.com/technetwork/java/javase/documentation/overview-156328.html#R160_141
core-libs/java.net
Additio
http://rhn.redhat.com/errata/RHSA-2017-0175.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0176.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0177.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0180.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0263.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0269.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0336.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0337.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0338.htmlhttp://www.debian.org/security/2017/dsa-3782http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.htmlhttp://www.securityfocus.com/bid/95563http://www.securitytracker.com/id/1037637https://access.redhat.com/errata/RHSA-2017:1216https://security.gentoo.org/glsa/201701-65https://security.gentoo.org/glsa/201707-01https://security.netapp.com/advisory/ntap-20170119-0001/http://rhn.redhat.com/errata/RHSA-2017-0175.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0176.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0177.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0180.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0263.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0269.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0336.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0337.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0338.htmlhttp://www.debian.org/security/2017/dsa-3782http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.htmlhttp://www.securityfocus.com/bid/95563http://www.securitytracker.com/id/1037637https://access.redhat.com/errata/RHSA-2017:1216https://security.gentoo.org/glsa/201701-65https://security.gentoo.org/glsa/201707-01https://security.netapp.com/advisory/ntap-20170119-0001/
2017-01-27
Published