GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sun Oct 29, 2017 11:26 pm Post subject: [ GLSA 201710-31 ] Oracle JDK/JRE |
|
|
Gentoo Linux Security Advisory
Title: Oracle JDK/JRE: Multiple vulnerabilities (GLSA 201710-31)
Severity: normal
Exploitable: remote
Date: 2017-10-29
Bug(s): #635030
ID: 201710-31
Synopsis
Multiple vulnerabilities have been found in Oracle's JDK and JRE
software suites, the worst of which can be remotely exploited without
authentication.
Background
Java Platform, Standard Edition (Java SE) lets you develop and deploy
Java applications on desktops and servers, as well as in today’s
demanding embedded environments. Java offers the rich user interface,
performance, versatility, portability, and security that today’s
applications require.
Affected Packages
Package: dev-java/oracle-jdk-bin
Vulnerable: < 1.8.0.152-r1
Unaffected: >= 1.8.0.152-r1
Architectures: All supported architectures
Package: dev-java/oracle-jre-bin
Vulnerable: < 1.8.0.152-r1
Unaffected: >= 1.8.0.152-r1
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in Oracle’s Java SE.
Please review the referenced CVE identifiers for details.
Impact
A remote attacker could cause a Denial of Service condition, modify
arbitrary data, or have numerous other impacts.
Workaround
There is no known workaround at this time.
Resolution
All Oracle JDK users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose
">=dev-java/oracle-jdk-bin-1.8.0.152-r1"
| All Oracle JRE users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose
">=dev-java/oracle-jre-bin-1.8.0.152-r1"
|
References
CVE-2017-10274
CVE-2017-10281
CVE-2017-10285
CVE-2017-10293
CVE-2017-10295
CVE-2017-10309
CVE-2017-10345
CVE-2017-10346
CVE-2017-10347
CVE-2017-10348
CVE-2017-10349
CVE-2017-10350
CVE-2017-10355
CVE-2017-10356
CVE-2017-10357
CVE-2017-10388
Last edited by GLSA on Mon Jan 15, 2018 4:16 am; edited 1 time in total |
|