PT-2016-1091 · Oracle+6 · Java Se Embedded+8

Publicado

2016-01-19

·

Atualizado

2024-06-15

·

CVE-2016-0494

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Java SE versions 6u105, 7u91, and 8u66 Java SE Embedded version 8u65 libpng (affected versions not specified)
Description The issue is related to errors in the code of the Java Platform's 2D subcomponent. Exploitation of this issue may allow a remote attacker to execute arbitrary code using network packets via Java Web Start or a Java applet. The vulnerability affects the confidentiality, integrity, and availability of the system via unknown vectors related to 2D. Additionally, libpng is vulnerable to a buffer overflow caused by a read underflow in png check keyword, which could allow a remote attacker to execute arbitrary code or cause the application to crash by sending an overly long argument.
Recommendations For Java SE versions 6u105, 7u91, and 8u66, update to a version that contains the fix for this issue. For Java SE Embedded version 8u65, update to a version that contains the fix for this issue. For libpng, as a temporary workaround, consider restricting the use of libpng until a patch is available. Avoid using libpng to process untrusted images until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for libpng.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00161
CESA-2016_0049
CESA-2016_0050
CESA-2016_0053
CESA-2016_0054
CESA-2016_0067
CVE-2016-0494
DLA-410-1
DLA-545-1
DSA-3458-1
DSA-3465-1
DSA-3725-1
MGASA-2016-0048
OPENSUSE-SU-2016_0263-1
OPENSUSE-SU-2016_0268-1
OPENSUSE-SU-2016_0270-1
OPENSUSE-SU-2016_0272-1
OPENSUSE-SU-2016_0279-1
OPENSUSE-SU-2024:10197-1
OPENSUSE-SU-2024:10534-1
RHSA-2016:0049
RHSA-2016:0050
RHSA-2016:0053
RHSA-2016:0054
RHSA-2016:0055
RHSA-2016:0056
RHSA-2016:0057
RHSA-2016:0067
RHSA-2016:0098
RHSA-2016:0099
RHSA-2016:0100
RHSA-2016:0101
RHSA-2016:1430
RHSA-2016_0049
RHSA-2016_0050
RHSA-2016_0053
RHSA-2016_0054
RHSA-2016_0055
RHSA-2016_0056
RHSA-2016_0057
RHSA-2016_0067
RHSA-2016_0098
RHSA-2016_0099
RHSA-2016_0101
SUSE-SU-2016:0256-1
SUSE-SU-2016:0265-1
SUSE-SU-2016:0269-1
SUSE-SU-2016:0390-1
SUSE-SU-2016:0399-1
SUSE-SU-2016:0401-1
SUSE-SU-2016:0428-1
SUSE-SU-2016:0431-1
SUSE-SU-2016:0433-1
SUSE-SU-2016:0636-1
SUSE-SU-2016:0770-1
USN-2884-1
USN-2885-1
USN-3227-1

Produtos afetados

Centos
Ibm Aix
Java Platform
Java Se
Java Se Embedded
Red Hat
Suse
Ubuntu
Libpng