CVE-2018-2790
published 2018-04-19CVE-2018-2790: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181…
PriorityP414low3.1CVSS 3.1
AVNACHPRNUIRSUCNILAN
EPSS
5.10%
91.5th percentile
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-8 | < openjdk-8 8u171-b11-1 (sid) | openjdk-8 8u171-b11-1 (sid) |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv3.1LOW
vendor_debian3.1LOW
vendor_redhat3.1LOW
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2018-06-21·CVSS 3.1
CVE-2018-2790 [LOW] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
It was discovered that the Security component of OpenJDK did not correctly
perform merging of multiple sections for the same file listed in JAR
archive file manifests. An attacker could possibly use this to modify
attributes in a manifest without invalidating the signature.
(CVE-2018-2790)
Francesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi
discovered that the Security component of OpenJDK did not restrict which
classes could be used when deserializing keys from the JCEKS key stores. An
attacker could use this to specially craft a JCEKS key store to execute
arbitrary code. (CVE-2018-2794)
It was discovered that the Security component of OpenJDK in some situations
did not pr
Ubuntu
OpenJDK 8 vulnerabilities
vendor_ubuntu·2018-05-11·CVSS 3.1
CVE-2018-2790 [LOW] OpenJDK 8 vulnerabilities
Title: OpenJDK 8 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 8.
It was discovered that the Security component of OpenJDK did not
correctly perform merging of multiple sections for the same file listed
in JAR archive file manifests. An attacker could possibly use this to
modify attributes in a manifest without invalidating the signature.
(CVE-2018-2790)
Francesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi
discovered that the Security component of OpenJDK did not restrict which
classes could be used when deserializing keys from the JCEKS key stores. An
attacker could use this to specially craft a JCEKS key store to execute
arbitrary code. (CVE-2018-2794)
It was discovered that the Security component of OpenJDK in some situations
did not pr
Red Hat
OpenJDK: incorrect merging of sections in the JAR manifest (Security, 8189969)
vendor_redhat·2018-04-17·CVSS 3.1
CVE-2018-2790 [LOW] CWE-347 OpenJDK: incorrect merging of sections in the JAR manifest (Security, 8189969)
OpenJDK: incorrect merging of sections in the JAR manifest (Security, 8189969)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or san
Debian
CVE-2018-2790: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subc...
vendor_debian·2018·CVSS 3.1
CVE-2018-2790 [LOW] CVE-2018-2790: openjdk-8 - Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subc...
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes fro
GHSA
GHSA-qjhg-jpxv-wj39: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security)
ghsa_unreviewed·2022-05-13
CVE-2018-2790 [LOW] GHSA-qjhg-jpxv-wj39: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes fro
OSV
openjdk-7 vulnerabilities
osv·2018-06-21·CVSS 3.1
CVE-2018-2790 [LOW] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
It was discovered that the Security component of OpenJDK did not correctly
perform merging of multiple sections for the same file listed in JAR
archive file manifests. An attacker could possibly use this to modify
attributes in a manifest without invalidating the signature.
(CVE-2018-2790)
Francesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi
discovered that the Security component of OpenJDK did not restrict which
classes could be used when deserializing keys from the JCEKS key stores. An
attacker could use this to specially craft a JCEKS key store to execute
arbitrary code. (CVE-2018-2794)
It was discovered that the Security component of OpenJDK in some situations
did not properly limit the amount of memory allocated when performing
deseri
OSV
openjdk-8 vulnerabilities
osv·2018-05-11·CVSS 3.1
CVE-2018-2790 [LOW] openjdk-8 vulnerabilities
openjdk-8 vulnerabilities
It was discovered that the Security component of OpenJDK did not
correctly perform merging of multiple sections for the same file listed
in JAR archive file manifests. An attacker could possibly use this to
modify attributes in a manifest without invalidating the signature.
(CVE-2018-2790)
Francesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi
discovered that the Security component of OpenJDK did not restrict which
classes could be used when deserializing keys from the JCEKS key stores. An
attacker could use this to specially craft a JCEKS key store to execute
arbitrary code. (CVE-2018-2794)
It was discovered that the Security component of OpenJDK in some situations
did not properly limit the amount of memory allocated when performing
deseri
OSV
CVE-2018-2790: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security)
osv·2018-04-18·CVSS 3.1
CVE-2018-2790 [LOW] CVE-2018-2790: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes fro
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10801 libtiff: memory leak in bmp2tiff tool
bugzilla·2018-05-11·CVSS 6.5
CVE-2018-10801 [MEDIUM] CVE-2018-10801 libtiff: memory leak in bmp2tiff tool
CVE-2018-10801 libtiff: memory leak in bmp2tiff tool
A flaw was found in LibTIFF 3.8.2TIFF. The ClientOpen function in tif_unix.c file has memory leaks which allow local attackers to cause a denial of service (memory consumption) via crafted file.
References:
http://bugzilla.maptools.org/show_bug.cgi?id=2790
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1577316]
Created mingw-libtiff tracking bugs for this issue:
Affects: epel-7 [bug 1577314]
Affects: fedora-all [bug 1577315]
---
In bmp2tiff tool a file is opened for writing with TIFFOpen, but when the iBitCount header value is wrong, the tool exits without closing the file.
Bugzilla
CVE-2018-2790 OpenJDK: incorrect merging of sections in the JAR manifest (Security, 8189969)
bugzilla·2018-04-17·CVSS 3.1
CVE-2018-2790 [LOW] CVE-2018-2790 OpenJDK: incorrect merging of sections in the JAR manifest (Security, 8189969)
CVE-2018-2790 OpenJDK: incorrect merging of sections in the JAR manifest (Security, 8189969)
It was discovered that the Security component of OpenJDK did not correctly perform merging of multiple sections for the same file listed in the JAR archive file manifest. An attacker could possibly use this flaw to alter certain attributes specified in the manifest without changing archive signature.
Discussion:
Public now via Oracle CPU April 2018:
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html#AppendixJAVA
The issue was fixed in Oracle JDK 10.0.1, 8u171, 7u181, and 6u191.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1188 https://access.redhat.com/errata/RHSA-2018:1188
---
This issue has been addressed
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.securityfocus.com/bid/103877http://www.securitytracker.com/id/1040697https://access.redhat.com/errata/RHSA-2018:1188https://access.redhat.com/errata/RHSA-2018:1191https://access.redhat.com/errata/RHSA-2018:1201https://access.redhat.com/errata/RHSA-2018:1202https://access.redhat.com/errata/RHSA-2018:1203https://access.redhat.com/errata/RHSA-2018:1204https://access.redhat.com/errata/RHSA-2018:1205https://access.redhat.com/errata/RHSA-2018:1206https://access.redhat.com/errata/RHSA-2018:1270https://access.redhat.com/errata/RHSA-2018:1278https://access.redhat.com/errata/RHSA-2018:1721https://access.redhat.com/errata/RHSA-2018:1722https://access.redhat.com/errata/RHSA-2018:1723https://access.redhat.com/errata/RHSA-2018:1724https://access.redhat.com/errata/RHSA-2018:1974https://access.redhat.com/errata/RHSA-2018:1975https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://security.gentoo.org/glsa/201903-14https://security.netapp.com/advisory/ntap-20180419-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03857en_ushttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03915en_ushttps://usn.ubuntu.com/3644-1/https://usn.ubuntu.com/3691-1/https://www.debian.org/security/2018/dsa-4185https://www.debian.org/security/2018/dsa-4225http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.securityfocus.com/bid/103877http://www.securitytracker.com/id/1040697https://access.redhat.com/errata/RHSA-2018:1188https://access.redhat.com/errata/RHSA-2018:1191https://access.redhat.com/errata/RHSA-2018:1201https://access.redhat.com/errata/RHSA-2018:1202https://access.redhat.com/errata/RHSA-2018:1203https://access.redhat.com/errata/RHSA-2018:1204https://access.redhat.com/errata/RHSA-2018:1205https://access.redhat.com/errata/RHSA-2018:1206https://access.redhat.com/errata/RHSA-2018:1270https://access.redhat.com/errata/RHSA-2018:1278https://access.redhat.com/errata/RHSA-2018:1721https://access.redhat.com/errata/RHSA-2018:1722https://access.redhat.com/errata/RHSA-2018:1723https://access.redhat.com/errata/RHSA-2018:1724https://access.redhat.com/errata/RHSA-2018:1974https://access.redhat.com/errata/RHSA-2018:1975https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://security.gentoo.org/glsa/201903-14https://security.netapp.com/advisory/ntap-20180419-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03857en_ushttps://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03915en_ushttps://usn.ubuntu.com/3644-1/https://usn.ubuntu.com/3691-1/https://www.debian.org/security/2018/dsa-4185https://www.debian.org/security/2018/dsa-4225
2018-04-19
Published