Lucene search

K
centosCentOS ProjectCESA-2016:0514
HistoryMar 25, 2016 - 3:43 a.m.

java security update

2016-03-2503:43:23
CentOS Project
lists.centos.org
51

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.036

Percentile

91.7%

CentOS Errata and Security Advisory CESA-2016:0514

The java-1.8.0-openjdk packages contain the latest version of the Open Java
Development Kit (OpenJDK), OpenJDK 8. These packages provide a fully compliant
implementation of Java SE 8.

Security Fix(es):

  • An improper type safety check was discovered in the Hotspot component. An
    untrusted Java application or applet could use this flaw to bypass Java Sandbox
    restrictions. (CVE-2016-0636)

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2016-March/083935.html

Affected packages:
java-1.8.0-openjdk
java-1.8.0-openjdk-debug
java-1.8.0-openjdk-demo
java-1.8.0-openjdk-demo-debug
java-1.8.0-openjdk-devel
java-1.8.0-openjdk-devel-debug
java-1.8.0-openjdk-headless
java-1.8.0-openjdk-headless-debug
java-1.8.0-openjdk-javadoc
java-1.8.0-openjdk-javadoc-debug
java-1.8.0-openjdk-src
java-1.8.0-openjdk-src-debug

Upstream details at:
https://access.redhat.com/errata/RHSA-2016:0514

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.036

Percentile

91.7%