Lack of data validation - Path Traversal In java-1.8.0-openjdk
Description
It was discovered that the LDAPCertStore class in the JNDI component of OpenJDK failed to securely handle LDAP referrals. An attacker could possibly use this flaw to make it fetch attacker controlled certificate data.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel7 | 1:1.8.0.161-0.b14.el7_4 | ||
rpm rhel7 | 1:1.7.0.171-2.6.13.0.el7_4 | ||
rpm rhel6 | 1:1.7.0.171-2.6.13.0.el6_9 | ||
rpm rhel6 | 1:1.8.0.161-3.b14.el6_9 | ||
rpm rhel6 | - | - |
Aliases
1. 2. 3.