Bug 41871 - openjdk-7: Multiple issues (4.1)
openjdk-7: Multiple issues (4.1)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.1
Other Linux
: P3 normal (vote)
: UCS 4.1-4-errata
Assigned To: Arvid Requate
Janek Walkenhorst
http://www.oracle.com/technetwork/sec...
:
Depends on:
Blocks: 41872
  Show dependency treegraph
 
Reported: 2016-07-28 18:29 CEST by Arvid Requate
Modified: 2017-02-01 12:07 CET (History)
3 users (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Security
Max CVSS v3 score:
requate: Patch_Available+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2016-07-28 18:29:00 CEST
The following issues have been reported as fixed by Oracle:

* Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; and Java SE Embedded 8u91 allows remote attackers to affect integrity via vectorsrelated to CORBA. (CVE-2016-3458)

* Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows remote attackers to affect availability via vectors related to JAXP, a different vulnerability than CVE-2016-3508. (CVE-2016-3500)

* Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; Java SE Embedded 8u91; and JRockit R28.3.10 allows remote attackers to affect availability via vectors related to JAXP, a different vulnerability than CVE-2016-3500. (CVE-2016-3508)

* Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality via vectors related to Hotspot. (CVE-2016-3550)

* Unspecified vulnerability in Oracle Java SE 7u101 and 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot. (CVE-2016-3606)
Comment 1 Arvid Requate univentionstaff 2016-08-09 18:38:55 CEST
Upstream Debian package version 7u111-2.6.7-1~deb7u1 fixes the issues above.
Comment 2 Arvid Requate univentionstaff 2016-11-08 20:21:55 CET
Upstream Debian package version 7u111-2.6.7-2~deb7u1 fixes

* Unspecified vulnerability in Oracle Java SE 7u111 allows remote attackers to affect integrity via vectors related to Libraries. (CVE-2016-5542)
* Unspecified vulnerability in Oracle Java SE 7u111 allows remote attackers to affect integrity via vectors related to JMX. (CVE-2016-5554)
* Unspecified vulnerability in Oracle Java SE 7u111 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5582. (CVE-2016-5573)
* Unspecified vulnerability in Oracle Java SE 7u111 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573. (CVE-2016-5582)
* Unspecified vulnerability in Oracle Java SE 7u111 allows remote attackers to affect confidentiality via vectors related to Networking. (CVE-2016-5597)
Comment 3 Stefan Gohmann univentionstaff 2016-12-21 06:28:07 CET
r75458:
Remove UCS 4.1-3 from YAML file since UCS 4.1-3 is no longer in maintenance (Bug #41871)
Comment 4 Arvid Requate univentionstaff 2017-01-25 20:26:32 CET
Upstream Debian package version 7u121-2.6.8-1~deb7u1 fixes:

     - S8165344, CVE-2017-3272: A protected field can be leveraged into type
       confusion.
     - S8167104, CVE-2017-3289: Custom class constructor code can bypass the
       required call to super.init allowing for uninitialized objects to be
       created.
     - S8156802, CVE-2017-3241: RMI deserialization should limit the types
       deserialized to prevent attacks that could escape the sandbox.
     - S8164143, CVE-2017-3260: It is possible to corrupt memory by calling
       dispose() on a CMenuComponentmultiple times.
     - S8168714, CVE-2016-5546: ECDSA will accept signatures that have various
       extraneous bytes added to them whereas the signature is supposed to be
       unique.
     - S8166988, CVE-2017-3253: The PNG specification allows the [iz}Txt
       sections to be 2^32-1 bytes long so these should not be uncompressed
       unless the user explicitly requests it.
     - S8168728, CVE-2016-5548: DSA signing exhibits a timing bias that may
       leak information about k.
     - S8168724, CVE-2016-5549: ECDSA signing exhibits a timing bias that may
       leak information about k.
     - S8161743, CVE-2017-3252: LdapLoginModule incorrectly tries to
       deserialize responses from an LDAP server when an LDAP context is
       expected.
     - S8167223, CVE-2016-5552: Parsing of URLs can be inconsistent with how
       users or external applications would interpret them leading to possible
       security issues.
     - S8168705, CVE-2016-5547: A value from an InputStream is read directly
       into the size argument of a new byte[] without validation.
     - S8164147, CVE-2017-3261: An integer overflow exists in
       SocketOutputStream which can lead to memorydisclosure.
     - S8151934, CVE-2017-3231: Under some circumstances URLClassLoader will
       dispatch HTTP GET requests where the invoker does not have permission.
     - S8165071, CVE-2016-2183: 3DES can be exploited for block collisions when
       long running sessions are allowed.

http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA
Comment 5 Arvid Requate univentionstaff 2017-01-25 20:51:29 CET
Imported and building.
Advisory: openjdk-7.yaml
Comment 6 Janek Walkenhorst univentionstaff 2017-01-26 19:09:06 CET
Tests (amd64): OK
Advisory: Some CVE seem to be not listed?
Comment 7 Arvid Requate univentionstaff 2017-01-30 11:40:44 CET
> Advisory: Some CVE seem to be not listed?

Yes, thanks to Oracle, no relevant details available.
Comment 8 Janek Walkenhorst univentionstaff 2017-01-31 10:24:56 CET
(In reply to Arvid Requate from comment #7)
> > Advisory: Some CVE seem to be not listed?
> 
> Yes, thanks to Oracle, no relevant details available.
OK
Comment 9 Janek Walkenhorst univentionstaff 2017-02-01 12:07:17 CET
<http://errata.software-univention.de/ucs/4.1/381.html>