CVE-2019-2697
published 2019-04-23CVE-2019-2697: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to…
PriorityP265high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EXPLOIT
EPSS
11.47%
95.5th percentile
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | openjdk-8 | — | — |
| hp | xp7_command_view | < 8.6.5-00 | 8.6.5-00 |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle_corporation | java | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | satellite | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Heap corruption triggered by loading a malicious TrueType Font (TTF) file via the Java 2D/t2k library; crash manifests in sc_FindExtrema4 inside libt2k.so during glyph rendering. ↗
- →Monitor Java processes loading external TTF font files via command-line arguments (e.g., DisplaySfntFont <file>.ttf) as an exploitation vector. ↗
- →Crash signature: invalid write/read in sc_FindExtrema4 called from fs_FindBitMapSize4 → MakeBWBits → T2K_RenderGlyphInternal → T2K_RenderGlyph → Java_sun_font_T2KFontScaler_getGlyphImageNative; use this call stack for memory-corruption detection rules. ↗
- →On Windows, enable PageHeap for java.exe to detect exploitation attempts; access violation at heap write (mov dword ptr [rax+rcx],1) is the observable crash signature. ↗
- →Vulnerability only applies to sandboxed Java Web Start applications or sandboxed Java applets (Java SE 8) loading untrusted code; monitor client-side Java deployments, not server-side. ↗
- ·Affected versions are Java SE 7u211 and 8u202 only; fixed in 7u221 and 8u211. Detections should be scoped to these version ranges. ↗
- ·The vulnerability does NOT affect server-side Java deployments running only trusted/administrator-installed code; tune detection rules to exclude such environments. ↗
- ·On Ubuntu, this issue only affected OpenJDK 8 in Ubuntu 16.04 LTS; scope Linux-based detections accordingly. ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1LOW
vendor_redhat8.1HIGH
vendor_ubuntu7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2019-05-13·CVSS 7.5
CVE-2019-2602 [HIGH] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
It was discovered that the BigDecimal implementation in OpenJDK performed
excessive computation when given certain values. An attacker could use this
to cause a denial of service (excessive CPU usage). (CVE-2019-2602)
Corwin de Boor and Robert Xiao discovered that the RMI registry
implementation in OpenJDK did not properly select the correct skeleton
class in some situations. An attacker could use this to possibly escape
Java sandbox restrictions. (CVE-2019-2684)
Mateusz Jurczyk discovered a vulnerability in the 2D component of
OpenJDK. An attacker could use this to possibly escape Java sandbox
restrictions. This issue only affected OpenJDK 8 in Ubuntu 16.04
LTS. (CVE-2019-2697)
Mateusz Jurczyk disc
Red Hat
JDK: Unspecified vulnerability fixed in 7u221 and 8u211 (2D)
vendor_redhat·2019-04-16·CVSS 8.1
CVE-2019-2697 [HIGH] JDK: Unspecified vulnerability fixed in 7u221 and 8u211 (2D)
JDK: Unspecified vulnerability fixed in 7u221 and 8u211 (2D)
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trus
Debian
CVE-2019-2697: openjdk-8 - Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Sup...
vendor_debian·2019·CVSS 8.1
CVE-2019-2697 [HIGH] CVE-2019-2697: openjdk-8 - Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Sup...
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0
GHSA
GHSA-rpf9-c8x3-2pp3: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D)
ghsa_unreviewed·2022-05-24
CVE-2019-2697 [HIGH] GHSA-rpf9-c8x3-2pp3: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D)
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0
OSV
openjdk-8, openjdk-lts vulnerabilities
osv·2019-05-13·CVSS 7.5
CVE-2019-2602 [HIGH] openjdk-8, openjdk-lts vulnerabilities
openjdk-8, openjdk-lts vulnerabilities
It was discovered that the BigDecimal implementation in OpenJDK performed
excessive computation when given certain values. An attacker could use this
to cause a denial of service (excessive CPU usage). (CVE-2019-2602)
Corwin de Boor and Robert Xiao discovered that the RMI registry
implementation in OpenJDK did not properly select the correct skeleton
class in some situations. An attacker could use this to possibly escape
Java sandbox restrictions. (CVE-2019-2684)
Mateusz Jurczyk discovered a vulnerability in the 2D component of
OpenJDK. An attacker could use this to possibly escape Java sandbox
restrictions. This issue only affected OpenJDK 8 in Ubuntu 16.04
LTS. (CVE-2019-2697)
Mateusz Jurczyk discovered a vulnerability in the font layout engine
OSV
CVE-2019-2697: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D)
osv·2019-04-23·CVSS 8.1
CVE-2019-2697 [HIGH] CVE-2019-2697: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D)
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0
No detection rules found.
Tenable
Oracle Critical Patch Update For April Contains 297 Fixes
blogs_tenable·2019-04-17
Oracle Critical Patch Update For April Contains 297 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2019-2697 Oracle JDK: Unspecified vulnerability fixed in 7u221 and 8u211 (2D)
bugzilla·2019-04-29·CVSS 8.1
CVE-2019-2697 [HIGH] CVE-2019-2697 Oracle JDK: Unspecified vulnerability fixed in 7u221 and 8u211 (2D)
CVE-2019-2697 Oracle JDK: Unspecified vulnerability fixed in 7u221 and 8u211 (2D)
Oracle Java SE 7u221 and 8u211 fixes an unspecified vulnerability in the 2D component (CVE-2019-2697). Upstream has CVSS scored this issue as: 8.1/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
External Reference:
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:1163 https://access.redhat.com/errata/RHSA-2019:1163
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Supplementary
Via RHSA-2019:1164 https://access.redhat.com/errata/RHSA-2019:1164
---
This issue has been addressed in the following produc
http://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://access.redhat.com/errata/RHSA-2019:1163https://access.redhat.com/errata/RHSA-2019:1164https://access.redhat.com/errata/RHSA-2019:1165https://access.redhat.com/errata/RHSA-2019:1166https://access.redhat.com/errata/RHSA-2019:1238https://access.redhat.com/errata/RHSA-2019:1325https://security.gentoo.org/glsa/201908-10https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03959en_ushttps://usn.ubuntu.com/3975-1/http://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://access.redhat.com/errata/RHSA-2019:1163https://access.redhat.com/errata/RHSA-2019:1164https://access.redhat.com/errata/RHSA-2019:1165https://access.redhat.com/errata/RHSA-2019:1166https://access.redhat.com/errata/RHSA-2019:1238https://access.redhat.com/errata/RHSA-2019:1325https://security.gentoo.org/glsa/201908-10https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03959en_ushttps://usn.ubuntu.com/3975-1/
2019-04-23
Published