Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Ubuntu 15.10 & 14.04 LTS USN-2942-1 Critical OpenJDK Denial Of Service

Ubuntu Large Esm H500
OpenJDK could be made to crash or run programs as your login if it received specially crafted input.
=========================================================================Ubuntu Security Notice USN-2942-1
March 24, 2016

openjdk-7 vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 14.04 LTS

Summary:

OpenJDK could be made to crash or run programs as your login if it received
specially crafted input.

Software Description:
- openjdk-7: Open Source Java implementation

Details:

A vulnerability was discovered in the JRE related to information
disclosure, data integrity, and availability. An attacker could exploit
these to cause a denial of service, expose sensitive data over the network,
or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  icedtea-7-jre-jamvm             7u95-2.6.4-0ubuntu0.15.10.2
  openjdk-7-jre                   7u95-2.6.4-0ubuntu0.15.10.2
  openjdk-7-jre-headless          7u95-2.6.4-0ubuntu0.15.10.2
  openjdk-7-jre-lib               7u95-2.6.4-0ubuntu0.15.10.2
  openjdk-7-jre-zero              7u95-2.6.4-0ubuntu0.15.10.2

Ubuntu 14.04 LTS:
  icedtea-7-jre-jamvm             7u95-2.6.4-0ubuntu0.14.04.2
  openjdk-7-jdk                   7u95-2.6.4-0ubuntu0.14.04.2
  openjdk-7-jre                   7u95-2.6.4-0ubuntu0.14.04.2
  openjdk-7-jre-headless          7u95-2.6.4-0ubuntu0.14.04.2
  openjdk-7-jre-lib               7u95-2.6.4-0ubuntu0.14.04.2
  openjdk-7-jre-zero              7u95-2.6.4-0ubuntu0.14.04.2

This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any Java
applications or applets to make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2942-1
  CVE-2016-0636

Package Information:
  https://launchpad.net/ubuntu/+source/openjdk-7/7u95-2.6.4-0ubuntu0.15.10.2
  https://launchpad.net/ubuntu/+source/openjdk-7/7u95-2.6.4-0ubuntu0.14.04.2

Ubuntu 15.10 & 14.04 LTS USN-2942-1 Critical OpenJDK Denial Of Service

ubuntu
Calendar Grey March 25, 2016
Dist Ubuntu Esm H88
Crucial OpenJDK 7 alert for Ubuntu users regarding a security vulnerability that impacts data accuracy and potential service disruptions.
OpenJDK could be made to crash or run programs as your login if it received specially crafted input.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10:   icedtea-7-jre-jamvm             7u95-2.6.4-0ubuntu0.15.10.2   openjdk-7-jre                   7u95-2.6.4-0ubuntu0.15.10.2   openjdk-7-jre-headless          7u95-2.6.4-0ubuntu0.15.10.2   openjdk-7-jre-lib               7u95-2.6.4-0ubuntu0.15.10.2   openjdk-7-jre-zero              7u95-2.6.4-0ubuntu0.15.10.2 Ubuntu 14.04 LTS:   icedtea-7-jre-jamvm             7u95-2.6.4-0ubuntu0.14.04.2   openjdk-7-jdk                   7u95-2.6.4-0ubuntu0.14.04.2   openjdk-7-jre                   7u95-2.6.4-0ubuntu0.14.04.2   openjdk-7-jre-headless          7u95-2.6.4-0ubuntu0.14.04.2   openjdk-7-jre-lib               7u95-2.6.4-0ubuntu0.14.04.2   openjdk-7-jre-zero              7u95-2.6.4-0ubuntu0.14.04.2 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart any Java applications or applets to make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-2942-1

  CVE-2016-0636

Severity
critical
Lowest
Low
Medium
High
Critical

March 24, 2016

Package Information

  https://launchpad.net/ubuntu/+source/openjdk-7/7u95-2.6.4-0ubuntu0.15.10.2   https://launchpad.net/ubuntu/+source/openjdk-7/7u95-2.6.4-0ubuntu0.14.04.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here