Insecure generation of random numbers In java-1.6.0-ibm
Description
It was discovered that the DNS client implementation in the JNDI component of OpenJDK did not use random source ports when sending out DNS queries. This could make it easier for a remote attacker to spoof responses to those queries.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel6 | - | - | |
rpm rhel6 | 1:1.7.0.171-2.6.13.0.el6_9 | ||
rpm rhel7 | 1:1.7.0.171-2.6.13.0.el7_4 | ||
rpm rhel7 | 1:1.8.0.161-0.b14.el7_4 | ||
rpm rhel6 | 1:1.8.0.161-3.b14.el6_9 |
Aliases
1. 2. 3.