PT-2017-11334 · Oracle+6 · Java Se Embedded+8
Published
2017-10-19
·
Updated
2024-06-15
·
CVE-2017-10357
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Java SE versions 6u161, 7u151, 8u144 and 9
Java SE Embedded version 8u144
Little CMS (affected versions not specified)
Description
The issue allows an unauthenticated attacker with network access via multiple protocols to compromise Java SE and Java SE Embedded, resulting in a partial denial of service. This vulnerability applies to Java deployments that load and run untrusted code and rely on the Java sandbox for security. It does not apply to Java deployments that load and run only trusted code. Additionally, Little CMS is vulnerable to a denial of service caused by an out-of-bounds read in the
Type MLU Read function, which can be exploited by a remote attacker using a specially-crafted image to cause the application to crash or obtain sensitive information.Recommendations
For Java SE versions 6u161, 7u151, 8u144 and 9, update to a version that contains a fix for this issue.
For Java SE Embedded version 8u144, update to a version that contains a fix for this issue.
For Little CMS, consider disabling the
Type MLU Read function in the cmstypes.c file as a temporary workaround until a patch is available.
Restrict access to untrusted code and ensure that only trusted code is loaded and run on servers to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Ibm Aix
Java Platform
Java Se
Java Se Embedded
Little Cms
Red Hat
Suse
Ubuntu