Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Ubuntu 15.10: USN-2818-1 Critical OpenJDK 7 Access Issue

ubuntu
Calendar Grey November 25, 2015
Scroller Ubuntu
OpenJDK 11 flaw rectified in Ubuntu distributions tackling severe permission problems. Confirm that system upgrades are executed.
A security issue was fixed in OpenJDK 7.

Summary

A security issue was fixed in OpenJDK 7.

Software Description:

- openjdk-7: Open Source Java implementation

Details:

It was discovered that rebinding of the receiver of a

DirectMethodHandle may allow a protected method to be accessed. Am

attacker could use this to expose sensitive information or possibly

execute arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  icedtea-7-jre-jamvm             7u91-2.6.3-0ubuntu0.15.10.1
  openjdk-7-jre                   7u91-2.6.3-0ubuntu0.15.10.1
  openjdk-7-jre-headless          7u91-2.6.3-0ubuntu0.15.10.1
  openjdk-7-jre-lib               7u91-2.6.3-0ubuntu0.15.10.1
  openjdk-7-jre-zero              7u91-2.6.3-0ubuntu0.15.10.1

Ubuntu 15.04:
  icedtea-7-jre-jamvm             7u91-2.6.3-0ubuntu0.15.04.1
  openjdk-7-jre                   7u91-2.6.3-0ubuntu0.15.04.1
  openjdk-7-jre-headless          7u91-2.6.3-0ubuntu0.15.04.1
  openjdk-7-jre-lib               7u91-2.6.3-0ubuntu0.15.04.1
  openjdk-7-jre-zero              7u91-2.6.3-0ubuntu0.15.04.1

Ubuntu 14.04 LTS:
  icedtea-7-jre-jamvm             7u91-2.6.3-0ubuntu0.14.04.1
  openjdk-7-jre                   7u91-2.6.3-0ubuntu0.14.04.1
  openjdk-7-jre-headless          7u91-2.6.3-0ubuntu0.14.04.1
  openjdk-7-jre-lib               7u91-2.6.3-0ubuntu0.14.04.1
  openjdk-7-jre-zero              7u91-2.6.3-0ubuntu0.14.04.1

After a standard system update you need to restart any Java
applications or applets to make all the necessary changes.

References

CVE-2015-4871

Severity
critical
Lowest
Low
Medium
High
Critical

November 25, 2015

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.