Junglewise Threat Intelligence

CVE-2016-5546: Oracle Java SE incorrect ECDSA signature extraction in Libraries

CVE-2016-5546 · Severity: high · CVSS 7.5 · Published 2017-01-27

Technologies: Oracle Java SE, Oracle JRockit, Oracle Java SE Embedded. Vendors: Oracle.

Executive brief

A vulnerability exists in the core libraries of Oracle Java SE, Java SE Embedded, and JRockit. This flaw allows an unauthenticated attacker to remotely modify or delete critical data within the Java environment. Such an exploit could compromise the integrity of applications running on both client and server deployments, potentially leading to unauthorized system changes or data corruption.

Technical details

The vulnerability is located in the Libraries subcomponent of Oracle Java SE, specifically involving incorrect ECDSA signature extraction from DER input. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via multiple protocols to compromise the integrity of the Java environment. The vulnerability can be triggered through sandboxed Java Web Start applications, sandboxed Java applets, or by supplying malicious data directly to affected APIs (e.g., via a web service). Successful exploitation results in unauthorized creation, deletion, or modification of data accessible to the Java runtime. The issue was addressed in Oracle's January 2017 Critical Patch Update (CPU).

Affected products

  • Oracle Java SE 6u131, 7u121, 8u112
  • Oracle Java SE Embedded 8u111
  • Oracle JRockit R28.3.12

Timeline

  • 2017-01-19: patched: Red Hat released security updates for affected Java packages.
  • 2017-01-27: disclosed: Public disclosure of the vulnerability.

References

Related threats