Multiple vulnerabilities have been found in Oracle's JRE and JDK software suites, and IcedTea, the worst of which may allow execution of arbitrary code. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201709-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Oracle JDK/JRE, IcedTea: Multiple vulnerabilities Date: September 24, 2017 Bugs: #625602, #626088, #627682 ID: 201709-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Oracle's JRE and JDK software suites, and IcedTea, the worst of which may allow execution of arbitrary code. Background ========= Java Platform, Standard Edition (Java SE) lets you develop and deploy Java applications on desktops and servers, as well as in today’s demanding embedded environments. Java offers the rich user interface, performance, versatility, portability, and security that today’s applications require. IcedTea’s aim is to provide OpenJDK in a form suitable for easy configuration, compilation and distribution with the primary goal of allowing inclusion in GNU/Linux distributions. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-java/oracle-jdk-bin < 1.8.0.141 > = 1.8.0.141 2 dev-java/oracle-jre-bin < 1.8.0.141 > = 1.8.0.141 3 dev-java/icedtea-bin < 3.5.0:8 *> = 3.5.0:8 < 7.2.6.11:7 *> = 7.2.6.11:7 ------------------------------------------------------------------- 3 affected packages Description ========== Multiple vulnerabilities have been discovered in Oracle’s JRE, JDK and IcedTea. Please review the referenced CVE identifiers for details. Impact ===== A remote attacker could possibly execute arbitrary code with the privileges of the process, cause a Denial of Service condition, or gain access to information. Workaround ========= There is no known workaround at this time. Resolution ========= All Oracle JDK binary users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =dev-java/oracle-jdk-bin-1.8.0.141" All Oracle JRE binary users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =dev-java/oracle-jre-bin-1.8.0.141" All IcedTea binary 7.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-java/icedtea-bin-7.2.6.11" All IcedTea binary 3.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-java/icedtea-bin-3.5.0" References ========= [ 1 ] CVE-2017-10053 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10053 [ 2 ] CVE-2017-10067 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10067 [ 3 ] CVE-2017-10074 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10074 [ 4 ] CVE-2017-10078 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10078 [ 5 ] CVE-2017-10081 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10081 [ 6 ] CVE-2017-10086 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10086 [ 7 ] CVE-2017-10087 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10087 [ 8 ] CVE-2017-10089 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10089 [ 9 ] CVE-2017-10090 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10090 [ 10 ] CVE-2017-10096 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10096 [ 11 ] CVE-2017-10101 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10101 [ 12 ] CVE-2017-10102 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10102 [ 13 ] CVE-2017-10105 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10105 [ 14 ] CVE-2017-10107 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10107 [ 15 ] CVE-2017-10108 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10108 [ 16 ] CVE-2017-10109 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10109 [ 17 ] CVE-2017-10110 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10110 [ 18 ] CVE-2017-10111 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10111 [ 19 ] CVE-2017-10114 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10114 [ 20 ] CVE-2017-10115 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10115 [ 21 ] CVE-2017-10116 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10116 [ 22 ] CVE-2017-10117 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10117 [ 23 ] CVE-2017-10118 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10118 [ 24 ] CVE-2017-10121 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10121 [ 25 ] CVE-2017-10125 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10125 [ 26 ] CVE-2017-10135 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10135 [ 27 ] CVE-2017-10176 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10176 [ 28 ] CVE-2017-10193 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10193 [ 29 ] CVE-2017-10198 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10198 [ 30 ] CVE-2017-10243 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10243 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201709-22 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been found in Oracle's JRE and JDK software suites allowing remote attackers to remotely execute arbitrary code, obtain information, and cause Denial of Service. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201610-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Oracle JRE/JDK: Multiple vulnerabilities Date: October 15, 2016 Bugs: #578160, #580608, #589208 ID: 201610-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Oracle's JRE and JDK software suites allowing remote attackers to remotely execute arbitrary code, obtain information, and cause Denial of Service. Background ========= Java Platform, Standard Edition (Java SE) lets you develop and deploy Java applications on desktops and servers, as well as in today’s demanding embedded environments. Java offers the rich user interface, performance, versatility, portability, and security that today’s applications require. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-java/oracle-jre-bin < 1.8.0.102 Vulnerable! < 1.8.0.102 2 dev-java/oracle-jdk-bin > = 1.8.0.102 > = 1.8.0.102 ------------------------------------------------------------------- NOTE: Certain packages are still vulnerable. Users should migrate to another package ifone is available or wait for the existing packages to be marked stable by their architecture maintainers. ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities exist in both Oracle’s JRE and JDK. Please review the referenced CVE’s for additional information. Impact ===== Remote attackers could gain access to information, remotely execute arbitrary code, or cause Denial of Service. Workaround ========= There is no known workaround at this time. Resolution ========= All Oracle JRE Users users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =dev-java/oracle-jdk-bin-1.8.0.102" All Oracle JDK Users users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =dev-java/oracle-jdk-bin-1.8.0.102" References ========= [ 1 ] CVE-2016-0402 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-0402 [ 2 ] CVE-2016-0448 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-0448 [ 3 ] CVE-2016-0466 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-0466 [ 4 ] CVE-2016-0475 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-0475 [ 5 ] CVE-2016-0483 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-0483 [ 6 ] CVE-2016-0494 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-0494 [ 7 ] CVE-2016-0603 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-0603 [ 8 ] CVE-2016-0636 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-0636 [ 9 ] CVE-2016-3426 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3426 [ 10 ] CVE-2016-3458 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3458 [ 11 ] CVE-2016-3485 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3485 [ 12 ] CVE-2016-3498 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3498 [ 13 ] CVE-2016-3500 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3500 [ 14 ] CVE-2016-3503 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3503 [ 15 ] CVE-2016-3508 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3508 [ 16 ] CVE-2016-3511 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3511 [ 17 ] CVE-2016-3550 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3550 [ 18 ] CVE-2016-3552 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3552 [ 19 ] CVE-2016-3587 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3587 [ 20 ] CVE-2016-3598 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3598 [ 21 ] CVE-2016-3606 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3606 [ 22 ] CVE-2016-3610 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-3610 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201610-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been found in Oracle JRE/JDK, allowing both local and remote attackers to compromise various Java components.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201507-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Oracle JRE/JDK: Multiple vulnerabilities Date: July 10, 2015 Bugs: #537214 ID: 201507-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Oracle JRE/JDK, allowing both local and remote attackers to compromise various Java components. Background ========= Oracle’s Java SE Development Kit and Runtime Environment Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-java/oracle-jre-bin < 1.8.0.31 > = 1.8.0.31 < 1.7.0.76 > = 1.7.0.76 2 dev-java/oracle-jdk-bin < 1.8.0.31 > = 1.8.0.31 < 1.7.0.76 > = 1.7.0.76 ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities have been discovered in Oracle JRE/JDK. Please review the CVE identifiers referenced below for details. Impact ===== An context-dependent attacker may be able to influence the confidentiality, integrity, and availability of Java applications/runtime. Workaround ========= There is no workaround at this time. Resolution ========= All Oracle JRE 8 users should upgrade to the latest stable version: #emerge --sync # emerge --ask --oneshot --verbose "> =dev-java/oracle-jre-bin-1.8.0.31 All Oracle JDK 8 users should upgrade to the latest stable version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-java/oracle-jdk-bin-1.8.0.31 All Oracle JRE 7 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-java/oracle-jre-bin-1.7.0.76 All Oracle JDK 7 users should upgrade to the latest stable version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-java/oracle-jdk-bin-1.7.0.76 References ========= [ 1 ] CVE-2014-3566 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-3566 [ 2 ] CVE-2014-6549 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6549 [ 3 ] CVE-2014-6585 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6585 [ 4 ] CVE-2014-6587 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6587 [ 5 ] CVE-2014-6591 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6591 [ 6 ] CVE-2014-6593 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6593 [ 7 ] CVE-2014-6601 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6601 [ 8 ] CVE-2015-0383 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0383 [ 9 ] CVE-2015-0395 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0395 [ 10 ] CVE-2015-0400 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0400 [ 11 ] CVE-2015-0403 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0403 [ 12 ] CVE-2015-0406 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0406 [ 13 ] CVE-2015-0407 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0407 [ 14 ] CVE-2015-0408 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0408 [ 15 ] CVE-2015-0410 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0410 [ 16 ] CVE-2015-0412 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0412 [ 17 ] CVE-2015-0413 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0413 [ 18 ] CVE-2015-0421 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0421 Availability =========== This GLSA and any updates to it areavailable for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201507-14 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.