CVE-2019-2949
published 2019-10-16CVE-2019-2949: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos). Supported versions that are affected are Java SE: 7u231, 8u221…
PriorityP338medium6.8CVSS 3.1
AVNACHPRNUINSCCHINAN
EPSS
3.60%
88.2th percentile
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-11 | < openjdk-11 11.0.5+10-1 (bullseye) | openjdk-11 11.0.5+10-1 (bullseye) |
| debian | openjdk-8 | < openjdk-11 11.0.5+10-1 (bullseye) | openjdk-11 11.0.5+10-1 (bullseye) |
| mcafee | epolicy_orchestrator | — | — |
| mcafee | epolicy_orchestrator | — | — |
| mcafee | epolicy_orchestrator | — | — |
| netapp | e-series_santricity_os_controller | 11.0.0 – 11.50.2 | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-522c-xxvj-5jhw: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos)
ghsa_unreviewed·2022-05-24
CVE-2019-2949 [MEDIUM] GHSA-522c-xxvj-5jhw: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos)
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrus
OSV
openjdk-8, openjdk-lts vulnerabilities
osv·2019-12-17·CVSS 3.7
CVE-2019-2894 [LOW] openjdk-8, openjdk-lts vulnerabilities
openjdk-8, openjdk-lts vulnerabilities
Jan Jancar, Petr Svenda, and Vladimir Sedlacek discovered that a side-
channel vulnerability existed in the ECDSA implementation in OpenJDK. An
Attacker could use this to expose sensitive information. (CVE-2019-2894)
It was discovered that the Socket implementation in OpenJDK did not
properly restrict the creation of subclasses with a custom Socket
implementation. An attacker could use this to specially create a Java class
that could possibly bypass Java sandbox restrictions. (CVE-2019-2945)
Rob Hamm discovered that the Kerberos implementation in OpenJDK did not
properly handle proxy credentials. An attacker could possibly use this to
impersonate another user. (CVE-2019-2949)
It was discovered that a NULL pointer dereference existed in the font
ha
OSV
CVE-2019-2949: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos)
osv·2019-10-16·CVSS 6.8
CVE-2019-2949 [MEDIUM] CVE-2019-2949: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos)
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrus
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2019-12-17·CVSS 3.7
CVE-2019-2894 [LOW] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
Jan Jancar, Petr Svenda, and Vladimir Sedlacek discovered that a side-
channel vulnerability existed in the ECDSA implementation in OpenJDK. An
Attacker could use this to expose sensitive information. (CVE-2019-2894)
It was discovered that the Socket implementation in OpenJDK did not
properly restrict the creation of subclasses with a custom Socket
implementation. An attacker could use this to specially create a Java class
that could possibly bypass Java sandbox restrictions. (CVE-2019-2945)
Rob Hamm discovered that the Kerberos implementation in OpenJDK did not
properly handle proxy credentials. An attacker could possibly use this to
impersonate another user. (CVE-2019-2949)
It was discovered that
Red Hat
OpenJDK: Improper handling of Kerberos proxy credentials (Kerberos, 8220302)
vendor_redhat·2019-10-15·CVSS 6.8
CVE-2019-2949 [MEDIUM] CWE-522 OpenJDK: Improper handling of Kerberos proxy credentials (Kerberos, 8220302)
OpenJDK: Improper handling of Kerberos proxy credentials (Kerberos, 8220302)
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start a
Debian
CVE-2019-2949: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (compon...
vendor_debian·2019·CVSS 6.8
CVE-2019-2949 [MEDIUM] CVE-2019-2949: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (compon...
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. While the vulnerability is in Java SE, Java SE Embedded, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrus
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-2949 OpenJDK: Improper handling of Kerberos proxy credentials (Kerberos, 8220302)
bugzilla·2019-10-14·CVSS 6.8
CVE-2019-2949 [MEDIUM] CVE-2019-2949 OpenJDK: Improper handling of Kerberos proxy credentials (Kerberos, 8220302)
CVE-2019-2949 OpenJDK: Improper handling of Kerberos proxy credentials (Kerberos, 8220302)
It was discovered that the Kerberos implementation in the Kerberos component in OpenJDK did not properly handle proxy credentials. This could lead to the unintended use of wrong credentials and possible user impersonation.
Discussion:
Public now via Oracle CPU October 2019:
https://www.oracle.com/security-alerts/cpuoct2019.html#AppendixJAVA
Fixed in Oracle Java SE 13.0.1, 11.0.5, 8u231, and 7u241.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:3128 https://access.redhat.com/errata/RHSA-2019:3128
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:3127 https://access.redhat.com/errata/
Bugzilla
CVE-2019-10055 suricata: denial of service in ftp_pasv_response
bugzilla·2019-09-05·CVSS 7.5
CVE-2019-10055 [HIGH] CVE-2019-10055 suricata: denial of service in ftp_pasv_response
CVE-2019-10055 suricata: denial of service in ftp_pasv_response
An issue was discovered in Suricata 4.1.3. The function ftp_pasv_response lacks a check for the length of part1 and part2, leading to a crash within the ftp/mod.rs file.
Reference:
https://redmine.openinfosecfoundation.org/issues/2949
https://suricata-ids.org/2019/04/30/suricata-4-1-4-released/
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://access.redhat.com/errata/RHSA-2019:3134https://access.redhat.com/errata/RHSA-2019:3135https://access.redhat.com/errata/RHSA-2019:3136https://kc.mcafee.com/corporate/index?page=content&id=SB10315https://lists.debian.org/debian-lts-announce/2019/12/msg00005.htmlhttps://seclists.org/bugtraq/2019/Oct/27https://seclists.org/bugtraq/2019/Oct/31https://security.netapp.com/advisory/ntap-20191017-0001/https://support.f5.com/csp/article/K54213762?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4223-1/https://www.debian.org/security/2019/dsa-4546https://www.debian.org/security/2019/dsa-4548http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://access.redhat.com/errata/RHSA-2019:3134https://access.redhat.com/errata/RHSA-2019:3135https://access.redhat.com/errata/RHSA-2019:3136https://kc.mcafee.com/corporate/index?page=content&id=SB10315https://lists.debian.org/debian-lts-announce/2019/12/msg00005.htmlhttps://seclists.org/bugtraq/2019/Oct/27https://seclists.org/bugtraq/2019/Oct/31https://security.netapp.com/advisory/ntap-20191017-0001/https://support.f5.com/csp/article/K54213762?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4223-1/https://www.debian.org/security/2019/dsa-4546https://www.debian.org/security/2019/dsa-4548
2019-10-16
Published