Lack of data validation - Path Traversal In java-1.8.0-openjdk
Description
It was discovered that the JCE component in OpenJDK failed to use constant time comparisons in multiple cases. An attacker could possibly use these flaws to disclose sensitive information by measuring the time used to perform operations using these non-constant time comparisons.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel7 | 1:1.8.0.51-1.b16.el7_1 | ||
rpm rhel7 | 1:1.7.0.85-2.6.1.2.el7_1 | ||
rpm rhel7 | 1:1.6.0.36-1.13.8.1.el7_1 | ||
rpm rhel6 | 1:1.7.0.85-2.6.1.3.el6_6 | ||
rpm rhel6 | 1:1.6.0.36-1.13.8.1.el6_7 | ||
rpm rhel5 | 1:1.7.0.85-2.6.1.3.el5_11 | ||
rpm rhel5 | 1:1.6.0.36-1.13.8.1.el5_11 | ||
rpm rhel6 | 1:1.8.0.51-0.b16.el6_6 |
Aliases
1. 2. 3.