Out-of-bounds read In java-1.8.0-openjdk
Description
It was discovered that the Libraries component of OpenJDK did not validate the length of the object identifier read from the DER input before allocating memory to store the OID. An attacker able to make a Java application decode a specially crafted DER input could cause the application to consume an excessive amount of memory.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel7 | 1:1.8.0.121-0.b13.el7_3 | ||
rpm rhel6 | 1:1.8.0.121-0.b13.el6_8 | ||
rpm rhel5 | 1:1.7.0.131-2.6.9.0.el5_11 | ||
rpm rhel7 | 1:1.7.0.131-2.6.9.0.el7_3 | ||
rpm rhel6 | 1:1.7.0.131-2.6.9.0.el6_8 |
Aliases
1. 2. 3.