Insecure digital certificates In java-1.7.0-openjdk
Description
It was discovered that the Security component of OpenJDK could fail to properly enforce restrictions defined for processing of X.509 certificate chains. A remote attacker could possibly use this flaw to make Java accept certificate using one of the disabled algorithms.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel6 | 1:1.7.0.161-2.6.12.0.el6_9 | ||
rpm rhel7 | 1:1.8.0.141-1.b16.el7_3 | ||
rpm rhel7 | 1:1.7.0.161-2.6.12.0.el7_4 | ||
rpm rhel6 | 1:1.8.0.141-2.b16.el6_9 |
Aliases
1. 2. 3.