Executive brief
A vulnerability exists in the core libraries of Oracle Java SE, Java SE Embedded, and JRockit. This flaw allows an unauthenticated attacker to remotely modify or delete critical data within the Java environment. Such an exploit could compromise the integrity of applications running on both client and server deployments, potentially leading to unauthorized system changes or data corruption.
Technical details
The vulnerability is located in the Libraries subcomponent of Oracle Java SE, specifically involving incorrect ECDSA signature extraction from DER input. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via multiple protocols to compromise the integrity of the Java environment. The vulnerability can be triggered through sandboxed Java Web Start applications, sandboxed Java applets, or by supplying malicious data directly to affected APIs (e.g., via a web service). Successful exploitation results in unauthorized creation, deletion, or modification of data accessible to the Java runtime. The issue was addressed in Oracle's January 2017 Critical Patch Update (CPU).
Affected products
- Oracle Java SE 6u131, 7u121, 8u112
- Oracle Java SE Embedded 8u111
- Oracle JRockit R28.3.12
Timeline
- 2017-01-19: patched: Red Hat released security updates for affected Java packages.
- 2017-01-27: disclosed: Public disclosure of the vulnerability.
References
- http://rhn.redhat.com/errata/RHSA-2017-0175.html
- http://rhn.redhat.com/errata/RHSA-2017-0176.html
- http://rhn.redhat.com/errata/RHSA-2017-0177.html
- http://rhn.redhat.com/errata/RHSA-2017-0180.html
- http://rhn.redhat.com/errata/RHSA-2017-0263.html
- http://rhn.redhat.com/errata/RHSA-2017-0269.html
- http://rhn.redhat.com/errata/RHSA-2017-0336.html