Use of insecure channel - Source code In java-1.8.0-openjdk
Description
It was discovered that the Kerberos client implementation in the Libraries component of OpenJDK used the sname field from the plain text part rather than encrypted part of the KDC reply message. A man-in-the-middle attacker could possibly use this flaw to impersonate Kerberos services to Java applications acting as Kerberos clients.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel7 | 1:1.8.0.151-1.b12.el7_4 | ||
rpm rhel6 | - | - | |
rpm rhel6 | 1:1.7.0.161-2.6.12.0.el6_9 | ||
rpm rhel7 | 1:1.7.0.161-2.6.12.0.el7_4 | ||
rpm rhel6 | 1:1.8.0.151-1.b12.el6_9 |
Aliases
1. 2. 3.