CVE-2018-2811
published 2018-04-19CVE-2018-2811: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install). Supported versions that are affected are Java SE: 8u162 and 10. Difficult to…
PriorityP434high7.7CVSS 3.1
AVLACHPRNUIRSCCHIHAH
EPSS
0.49%
38.9th percentile
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install). Supported versions that are affected are Java SE: 8u162 and 10. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: Applies to installation process on client deployment of Java. CVSS 3.0 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjdk-8 | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| schneider-electric | struxureware_data_center_expert | < 7.6.0 | 7.6.0 |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.03.7LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
vendor_debian7.7LOW
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-688j-c22c-v56f: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install)
ghsa_unreviewed·2022-05-13
CVE-2018-2811 [HIGH] GHSA-688j-c22c-v56f: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install)
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install). Supported versions that are affected are Java SE: 8u162 and 10. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: Applies to installation process on client deployment of Java. CVSS 3.0 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
Red Hat
JDK: unspecified vulnerability fixed in 8u171 and 10.0.1 (Install)
vendor_redhat·2018-04-17·CVSS 7.7
CVE-2018-2811 [HIGH] JDK: unspecified vulnerability fixed in 8u171 and 10.0.1 (Install)
JDK: unspecified vulnerability fixed in 8u171 and 10.0.1 (Install)
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install). Supported versions that are affected are Java SE: 8u162 and 10. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: Applies to installation process on client deployment of Java. CVSS 3.0 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N
Debian
CVE-2018-2811: openjdk-8 - Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install)...
vendor_debian·2018·CVSS 7.7
CVE-2018-2811 [HIGH] CVE-2018-2811: openjdk-8 - Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install)...
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install). Supported versions that are affected are Java SE: 8u162 and 10. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: Applies to installation process on client deployment of Java. CVSS 3.0 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
Scope: local
sid: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-17000 libtiff: NULL pointer dereference in function _TIFFmemcmp at tif_unix.c
bugzilla·2018-09-17·CVSS 6.5
CVE-2018-17000 [MEDIUM] CVE-2018-17000 libtiff: NULL pointer dereference in function _TIFFmemcmp at tif_unix.c
CVE-2018-17000 libtiff: NULL pointer dereference in function _TIFFmemcmp at tif_unix.c
A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an attacker to cause a denial-of-service through a crafted tiff file. This vulnerability can be triggered by the executable tiffcp.
Upstream bug:
http://bugzilla.maptools.org/show_bug.cgi?id=2811
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1630006]
Created mingw-libtiff tracking bugs for this issue:
Affects: epel-7 [bug 1630009]
Affects: fedora-all [bug 1630007]
---
Analysis:
It seems like the flaw was introduced after libtiff-4.0.9 was released. So this is likely a regression in the unreleased version of libtif
Bugzilla
CVE-2018-2811 Oracle JDK: unspecified vulnerability fixed in 8u171 and 10.0.1 (Install)
bugzilla·2018-04-18·CVSS 7.7
CVE-2018-2811 [HIGH] CVE-2018-2811 Oracle JDK: unspecified vulnerability fixed in 8u171 and 10.0.1 (Install)
CVE-2018-2811 Oracle JDK: unspecified vulnerability fixed in 8u171 and 10.0.1 (Install)
Oracle Java SE 8u171 and 10.0.1 fixes an unspecified vulnerability in the Install component (CVE-2018-2811). Upstream has CVSS scored this issue as: 7.7/CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
External Reference:
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 6
Via RHSA-2018:1202 https://access.redhat.com/errata/RHSA-2018:1202
---
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 7
Via RHSA-2018:1204 https://access.redhat.com/errata/RHSA-2018:1204
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.securityfocus.com/bid/103810http://www.securitytracker.com/id/1040697https://access.redhat.com/errata/RHSA-2018:1202https://access.redhat.com/errata/RHSA-2018:1204https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://security.gentoo.org/glsa/201903-14https://security.netapp.com/advisory/ntap-20180419-0001/http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.securityfocus.com/bid/103810http://www.securitytracker.com/id/1040697https://access.redhat.com/errata/RHSA-2018:1202https://access.redhat.com/errata/RHSA-2018:1204https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0https://security.gentoo.org/glsa/201903-14https://security.netapp.com/advisory/ntap-20180419-0001/
2018-04-19
Published