CVE-2019-2964
published 2019-10-16CVE-2019-2964: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231…
PriorityP415low3.7CVSS 3.1
AVNACHPRNUINSUCNINAL
EPSS
3.53%
88.0th percentile
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openjdk-11 | < openjdk-11 11.0.5+10-1 (bullseye) | openjdk-11 11.0.5+10-1 (bullseye) |
| debian | openjdk-8 | < openjdk-11 11.0.5+10-1 (bullseye) | openjdk-11 11.0.5+10-1 (bullseye) |
| netapp | e-series_santricity_os_controller | 11.0.0 – 11.50.2 | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle_corporation | java | — | — |
| oracle_corporation | java | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv3.7LOW
vendor_debian3.7LOW
vendor_redhat3.7LOW
vendor_ubuntu3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5gmg-gq5q-xv3f: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency)
ghsa_unreviewed·2022-05-24
CVE-2019-2964 [MEDIUM] GHSA-5gmg-gq5q-xv3f: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency)
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:
OSV
openjdk-8, openjdk-lts vulnerabilities
osv·2019-12-17·CVSS 3.7
CVE-2019-2894 [LOW] openjdk-8, openjdk-lts vulnerabilities
openjdk-8, openjdk-lts vulnerabilities
Jan Jancar, Petr Svenda, and Vladimir Sedlacek discovered that a side-
channel vulnerability existed in the ECDSA implementation in OpenJDK. An
Attacker could use this to expose sensitive information. (CVE-2019-2894)
It was discovered that the Socket implementation in OpenJDK did not
properly restrict the creation of subclasses with a custom Socket
implementation. An attacker could use this to specially create a Java class
that could possibly bypass Java sandbox restrictions. (CVE-2019-2945)
Rob Hamm discovered that the Kerberos implementation in OpenJDK did not
properly handle proxy credentials. An attacker could possibly use this to
impersonate another user. (CVE-2019-2949)
It was discovered that a NULL pointer dereference existed in the font
ha
OSV
CVE-2019-2964: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency)
osv·2019-10-16·CVSS 3.7
CVE-2019-2964 [LOW] CVE-2019-2964: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency)
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2019-12-17·CVSS 3.7
CVE-2019-2894 [LOW] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
Jan Jancar, Petr Svenda, and Vladimir Sedlacek discovered that a side-
channel vulnerability existed in the ECDSA implementation in OpenJDK. An
Attacker could use this to expose sensitive information. (CVE-2019-2894)
It was discovered that the Socket implementation in OpenJDK did not
properly restrict the creation of subclasses with a custom Socket
implementation. An attacker could use this to specially create a Java class
that could possibly bypass Java sandbox restrictions. (CVE-2019-2945)
Rob Hamm discovered that the Kerberos implementation in OpenJDK did not
properly handle proxy credentials. An attacker could possibly use this to
impersonate another user. (CVE-2019-2949)
It was discovered that
Red Hat
OpenJDK: Unexpected exception thrown by Pattern processing crafted regular expression (Concurrency, 8222684)
vendor_redhat·2019-10-15·CVSS 3.7
CVE-2019-2964 [LOW] CWE-248 OpenJDK: Unexpected exception thrown by Pattern processing crafted regular expression (Concurrency, 8222684)
OpenJDK: Unexpected exception thrown by Pattern processing crafted regular expression (Concurrency, 8222684)
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets,
Debian
CVE-2019-2964: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (compon...
vendor_debian·2019·CVSS 3.7
CVE-2019-2964 [LOW] CVE-2019-2964: openjdk-11 - Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (compon...
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-16723 cacti: Authentication bypass via graph_json.php request
bugzilla·2019-11-06·CVSS 4.3
CVE-2019-16723 [MEDIUM] CVE-2019-16723 cacti: Authentication bypass via graph_json.php request
CVE-2019-16723 cacti: Authentication bypass via graph_json.php request
In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.
Upstream issue:
https://github.com/Cacti/cacti/issues/2964
Discussion:
Created cacti tracking bugs for this issue:
Affects: epel-all [bug 1769554]
Affects: fedora-all [bug 1769552]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.
Bugzilla
CVE-2019-2964 OpenJDK: Unexpected exception thrown by Pattern processing crafted regular expression (Concurrency, 8222684)
bugzilla·2019-10-11·CVSS 3.7
CVE-2019-2964 [LOW] CVE-2019-2964 OpenJDK: Unexpected exception thrown by Pattern processing crafted regular expression (Concurrency, 8222684)
CVE-2019-2964 OpenJDK: Unexpected exception thrown by Pattern processing crafted regular expression (Concurrency, 8222684)
It was discovered that the Pattern class in the Concurrency component in OpenJDK could throw an unexpected StackOverflowError exception when compiling specially crafted regular expression. This could possibly cause a Java application to exit because of an unhandled exception if it processed untrusted regular expressions.
Discussion:
Public now via Oracle CPU October 2019:
https://www.oracle.com/security-alerts/cpuoct2019.html#AppendixJAVA
Fixed in Oracle Java SE 13.0.1, 11.0.5, 8u231, and 7u241.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:3128 https://access.redhat.com/errata/RHSA-2019:3128
---
This i
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://access.redhat.com/errata/RHSA-2019:3134https://access.redhat.com/errata/RHSA-2019:3135https://access.redhat.com/errata/RHSA-2019:3136https://access.redhat.com/errata/RHSA-2019:3157https://access.redhat.com/errata/RHSA-2019:3158https://access.redhat.com/errata/RHSA-2019:4109https://access.redhat.com/errata/RHSA-2019:4110https://access.redhat.com/errata/RHSA-2019:4113https://access.redhat.com/errata/RHSA-2019:4115https://access.redhat.com/errata/RHSA-2020:0006https://access.redhat.com/errata/RHSA-2020:0046https://lists.debian.org/debian-lts-announce/2019/12/msg00005.htmlhttps://seclists.org/bugtraq/2019/Oct/27https://seclists.org/bugtraq/2019/Oct/31https://security.netapp.com/advisory/ntap-20191017-0001/https://usn.ubuntu.com/4223-1/https://www.debian.org/security/2019/dsa-4546https://www.debian.org/security/2019/dsa-4548http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00064.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00031.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://access.redhat.com/errata/RHSA-2019:3134https://access.redhat.com/errata/RHSA-2019:3135https://access.redhat.com/errata/RHSA-2019:3136https://access.redhat.com/errata/RHSA-2019:3157https://access.redhat.com/errata/RHSA-2019:3158https://access.redhat.com/errata/RHSA-2019:4109https://access.redhat.com/errata/RHSA-2019:4110https://access.redhat.com/errata/RHSA-2019:4113https://access.redhat.com/errata/RHSA-2019:4115https://access.redhat.com/errata/RHSA-2020:0006https://access.redhat.com/errata/RHSA-2020:0046https://lists.debian.org/debian-lts-announce/2019/12/msg00005.htmlhttps://seclists.org/bugtraq/2019/Oct/27https://seclists.org/bugtraq/2019/Oct/31https://security.netapp.com/advisory/ntap-20191017-0001/https://usn.ubuntu.com/4223-1/https://www.debian.org/security/2019/dsa-4546https://www.debian.org/security/2019/dsa-4548
2019-10-16
Published