Insecure encryption algorithm In java-1.6.0-openjdk
Description
It was discovered that the Libraries component of OpenJDK did not restrict the set of algorithms used for JAR integrity verification. This flaw could allow an attacker to modify content of the JAR file that used weak signing key or hash algorithm.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel6 | 1:1.6.0.41-1.13.13.1.el6_8 | ||
rpm rhel7 | 1:1.6.0.41-1.13.13.1.el7_3 | ||
rpm rhel6 | 1:1.8.0.111-0.b15.el6_8 | ||
rpm rhel5 | 1:1.7.0.121-2.6.8.1.el5_11 | ||
rpm rhel7 | 1:1.7.0.121-2.6.8.0.el7_3 | ||
rpm rhel5 | 1:1.6.0.41-1.13.13.1.el5_11 | ||
rpm rhel6 | 1:1.7.0.121-2.6.8.1.el6_8 | ||
rpm rhel7 | 1:1.8.0.111-1.b15.el7_2 |
Aliases
1. 2. 3.