CVE-2017-3544
published 2017-04-24CVE-2017-3544: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java…
PriorityP415low3.7CVSS 3.0
AVNACHPRNUINSUCNILAN
EPSS
1.69%
74.4th percentile
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | openjdk-8 | < openjdk-8 8u131-b11-1 (sid) | openjdk-8 8u131-b11-1 (sid) |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jrockit | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.03.7LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.2MEDIUM
vendor_ubuntu4.2MEDIUM
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2017-3544: Android Security Bulletin 2017-07-01
CVE: CVE-2017-3544
Severity: MEDIUM
Type: RCE
Affected AOSP versions: 4
vendor_android·2017-07-01·CVSS 3.7
CVE-2017-3544 [LOW] CVE-2017-3544: Android Security Bulletin 2017-07-01
CVE: CVE-2017-3544
Severity: MEDIUM
Type: RCE
Affected AOSP versions: 4
Android Security Bulletin 2017-07-01
CVE: CVE-2017-3544
Severity: MEDIUM
Type: RCE
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2
References: A-35784677
Ubuntu
OpenJDK 7 regression
vendor_ubuntu·2017-05-18·CVSS 4.2
[MEDIUM] OpenJDK 7 regression
Title: OpenJDK 7 regression
Summary: USN-3275-2 introduced a regression in OpenJDK 7.
USN-3275-2 fixed vulnerabilities in OpenJDK 7. Unfortunately, the
update introduced a regression when handling TLS handshakes. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that OpenJDK improperly re-used cached NTLM
connections in some situations. A remote attacker could possibly
use this to cause a Java application to perform actions with the
credentials of a different user. (CVE-2017-3509)
It was discovered that an untrusted library search path flaw existed
in the Java Cryptography Extension (JCE) component of OpenJDK. A
local attacker could possibly use this to gain the privileges of a
Java application. (CVE-2017-3511)
It was dis
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2017-05-15·CVSS 4.2
CVE-2017-3509 [MEDIUM] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
USN-3275-1 fixed vulnerabilities in OpenJDK 8. This update provides
the corresponding updates for OpenJDK 7.
Original advisory details:
It was discovered that OpenJDK improperly re-used cached NTLM
connections in some situations. A remote attacker could possibly
use this to cause a Java application to perform actions with the
credentials of a different user. (CVE-2017-3509)
It was discovered that an untrusted library search path flaw existed
in the Java Cryptography Extension (JCE) component of OpenJDK. A
local attacker could possibly use this to gain the privileges of a
Java application. (CVE-2017-3511)
It was discovered that the Java API for XML Processing (JAXP) component
in OpenJDK did not
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2017-05-11·CVSS 4.2
CVE-2017-3509 [MEDIUM] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
It was discovered that OpenJDK improperly re-used cached NTLM
connections in some situations. A remote attacker could possibly
use this to cause a Java application to perform actions with the
credentials of a different user. (CVE-2017-3509)
It was discovered that an untrusted library search path flaw existed
in the Java Cryptography Extension (JCE) component of OpenJDK. A
local attacker could possibly use this to gain the privileges of a
Java application. (CVE-2017-3511)
It was discovered that the Java API for XML Processing (JAXP) component
in OpenJDK did not properly enforce size limits when parsing XML
documents. An attacker could use this to cause a denial of service
(processor and memory con
Red Hat
OpenJDK: newline injection in the SMTP client (Networking, 8171533)
vendor_redhat·2017-04-18·CVSS 3.7
CVE-2017-3544 [LOW] CWE-20 OpenJDK: newline injection in the SMTP client (Networking, 8171533)
OpenJDK: newline injection in the SMTP client (Networking, 8171533)
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by
Debian
CVE-2017-3544: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java...
vendor_debian·2017·CVSS 3.7
CVE-2017-3544 [LOW] CVE-2017-3544: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java...
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sand
GHSA
GHSA-x9hr-p2wg-6f69: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking)
ghsa_unreviewed·2022-05-13
CVE-2017-3544 [MEDIUM] GHSA-x9hr-p2wg-6f69: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking)
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sand
OSV
openjdk-7 regression
osv·2017-05-18·CVSS 4.2
CVE-2017-3509 [MEDIUM] openjdk-7 regression
openjdk-7 regression
USN-3275-2 fixed vulnerabilities in OpenJDK 7. Unfortunately, the
update introduced a regression when handling TLS handshakes. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that OpenJDK improperly re-used cached NTLM
connections in some situations. A remote attacker could possibly
use this to cause a Java application to perform actions with the
credentials of a different user. (CVE-2017-3509)
It was discovered that an untrusted library search path flaw existed
in the Java Cryptography Extension (JCE) component of OpenJDK. A
local attacker could possibly use this to gain the privileges of a
Java application. (CVE-2017-3511)
It was discovered that the Java API for XML Processing (JAXP) component
in O
OSV
openjdk-7 vulnerabilities
osv·2017-05-15·CVSS 4.2
CVE-2017-3509 [MEDIUM] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
USN-3275-1 fixed vulnerabilities in OpenJDK 8. This update provides
the corresponding updates for OpenJDK 7.
Original advisory details:
It was discovered that OpenJDK improperly re-used cached NTLM
connections in some situations. A remote attacker could possibly
use this to cause a Java application to perform actions with the
credentials of a different user. (CVE-2017-3509)
It was discovered that an untrusted library search path flaw existed
in the Java Cryptography Extension (JCE) component of OpenJDK. A
local attacker could possibly use this to gain the privileges of a
Java application. (CVE-2017-3511)
It was discovered that the Java API for XML Processing (JAXP) component
in OpenJDK did not properly enforce size limits when parsing XML
documents. An attack
OSV
openjdk-8 vulnerabilities
osv·2017-05-11·CVSS 4.2
CVE-2017-3509 [MEDIUM] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
It was discovered that OpenJDK improperly re-used cached NTLM
connections in some situations. A remote attacker could possibly
use this to cause a Java application to perform actions with the
credentials of a different user. (CVE-2017-3509)
It was discovered that an untrusted library search path flaw existed
in the Java Cryptography Extension (JCE) component of OpenJDK. A
local attacker could possibly use this to gain the privileges of a
Java application. (CVE-2017-3511)
It was discovered that the Java API for XML Processing (JAXP) component
in OpenJDK did not properly enforce size limits when parsing XML
documents. An attacker could use this to cause a denial of service
(processor and memory consumption). (CVE-2017-3526)
It was discovered that the FTP client
OSV
CVE-2017-3544: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking)
osv·2017-04-24·CVSS 3.7
CVE-2017-3544 [LOW] CVE-2017-3544: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking)
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sand
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-3544 OpenJDK: newline injection in the SMTP client (Networking, 8171533)
bugzilla·2017-04-18·CVSS 3.7
CVE-2017-3544 [LOW] CVE-2017-3544 OpenJDK: newline injection in the SMTP client (Networking, 8171533)
CVE-2017-3544 OpenJDK: newline injection in the SMTP client (Networking, 8171533)
It was discovered that the SMTP client implementation in the Networking component of OpenJDK failed to correctly handle sender and recipient addresses containing newline characters. A remote attacker could possibly use this flaw to manipulate an SMTP connection opened by a Java application if it could make it send an email to or from a specially crafted address.
Discussion:
Public now via Oracle CPU April 20167, fixed in Oracle JDK 8u131, 7u141, and 6u151.
External References:
http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html#AppendixJAVA
---
OpenJDK8 upstream commit:
http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/f672cb804684
---
This issue has been addressed in the follow
Checkpoint
2017-7-10 Global Cyber Attack Reports
blogs_checkpoint·2017-07-10
CVE-2017-3544 2017-7-10 Global Cyber Attack Reports
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 2017-7-10 Global Cyber Attack Reports
TOP ATTACKS AND BREACHES
Security researchers have found an unsecured Amazon S3 server belonging to the World Wrestling Entertainment (WWE), which led to the possible exposure of sensitive data of over 3 million registeredusers. The researchers have also found a second database that included statistical marketing data.
The South Korean cryptocurrency exchange, Bithumb, has suffered a security breach in which threat actors have managed to steal sensitive information of the f
http://www.debian.org/security/2017/dsa-3858http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.securityfocus.com/bid/97745http://www.securitytracker.com/id/1038286https://access.redhat.com/errata/RHSA-2017:1108https://access.redhat.com/errata/RHSA-2017:1109https://access.redhat.com/errata/RHSA-2017:1117https://access.redhat.com/errata/RHSA-2017:1118https://access.redhat.com/errata/RHSA-2017:1119https://access.redhat.com/errata/RHSA-2017:1204https://access.redhat.com/errata/RHSA-2017:1220https://access.redhat.com/errata/RHSA-2017:1221https://access.redhat.com/errata/RHSA-2017:1222https://access.redhat.com/errata/RHSA-2017:3453https://security.gentoo.org/glsa/201705-03https://security.gentoo.org/glsa/201707-01https://source.android.com/security/bulletin/2017-07-01http://www.debian.org/security/2017/dsa-3858http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.securityfocus.com/bid/97745http://www.securitytracker.com/id/1038286https://access.redhat.com/errata/RHSA-2017:1108https://access.redhat.com/errata/RHSA-2017:1109https://access.redhat.com/errata/RHSA-2017:1117https://access.redhat.com/errata/RHSA-2017:1118https://access.redhat.com/errata/RHSA-2017:1119https://access.redhat.com/errata/RHSA-2017:1204https://access.redhat.com/errata/RHSA-2017:1220https://access.redhat.com/errata/RHSA-2017:1221https://access.redhat.com/errata/RHSA-2017:1222https://access.redhat.com/errata/RHSA-2017:3453https://security.gentoo.org/glsa/201705-03https://security.gentoo.org/glsa/201707-01https://source.android.com/security/bulletin/2017-07-01
2017-04-24
Published