Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in OpenJDK 8.
Software Description:
- openjdk-8: Open Source Java implementation
Details:
It was discovered that the Smart Card IO subsystem in OpenJDK did not
properly maintain state. An attacker could use this to specially construct
an untrusted Java application or applet to gain access to a smart card,
bypassing sandbox restrictions. (CVE-2017-10274)
Gaston Traberg discovered that the Serialization component of OpenJDK did
not properly limit the amount of memory allocated when performing
deserializations. An attacker could use this to cause a denial of service
(memory exhaustion). (CVE-2017-10281)
It was discovered that the Remote Method Invocation (RMI) component in
OpenJDK did not properly handle unreferenced objects. An attacker could use
this to specially construct an untrusted Java application or applet that
could escape sandbox restrictions. (CVE-2017-10285)
It was discovered that the HTTPUrlConnection classes in OpenJDK did not
pro...
The problem can be corrected by updating your system to the following package versions: Ubuntu 17.10: openjdk-8-jdk 8u151-b12-0ubuntu0.17.10.2 openjdk-8-jdk-headless 8u151-b12-0ubuntu0.17.10.2 openjdk-8-jre 8u151-b12-0ubuntu0.17.10.2 openjdk-8-jre-headless 8u151-b12-0ubuntu0.17.10.2 openjdk-8-jre-zero 8u151-b12-0ubuntu0.17.10.2 Ubuntu 17.04: openjdk-8-jdk 8u151-b12-0ubuntu0.17.04.2 openjdk-8-jdk-headless 8u151-b12-0ubuntu0.17.04.2 openjdk-8-jre 8u151-b12-0ubuntu0.17.04.2 openjdk-8-jre-headless 8u151-b12-0ubuntu0.17.04.2 openjdk-8-jre-zero 8u151-b12-0ubuntu0.17.04.2 Ubuntu 16.04 LTS: openjdk-8-jdk 8u151-b12-0ubuntu0.16.04.2 openjdk-8-jdk-headless 8u151-b12-0ubuntu0.16.04.2 openjdk-8-jre 8u151-b12-0ubuntu0.16.04.2 openjdk-8-jre-headless 8u151-b12-0ubuntu0.16.04.2 openjdk-8-jre-jamvm 8u151-b12-0ubuntu0.16.04.2 openjdk-8-jre-zero 8u151-b12-0ubuntu0.16.04.2 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart any Java applications or applets to make all the necessary changes.
https://ubuntu.com/security/notices/USN-3473-1
CVE-2017-10274, CVE-2017-10281, CVE-2017-10285, CVE-2017-10295,
CVE-2017-10345, CVE-2017-10346, CVE-2017-10347, CVE-2017-10348,
CVE-2017-10349, CVE-2017-10350, CVE-2017-10355, CVE-2017-10356,
CVE-2017-10357, CVE-2017-10388
Get the latest Linux and open source security news straight to your inbox.