Junglewise Threat Intelligence

CVE-2016-5547: Oracle Java SE denial of service in Libraries component

CVE-2016-5547 · Severity: medium · CVSS 5.3 · Published 2017-01-27

Technologies: Oracle Java SE, Oracle JRockit, Oracle Java SE Embedded. Vendors: Oracle.

Executive brief

A vulnerability exists in the Libraries subcomponent of Oracle Java SE, Java SE Embedded, and JRockit. This flaw allows an unauthenticated remote attacker to cause a partial denial of service, potentially impacting the availability of applications and services running on the affected Java versions. The issue affects both client and server deployments, including web services and sandboxed applications like Java Web Start.

Technical details

A vulnerability in the Libraries subcomponent of Oracle Java SE (specifically versions 7u121 and 8u112), Java SE Embedded (8u111), and JRockit (R28.3.12) is caused by a missing length check for ObjectIdentifiers. An unauthenticated attacker can exploit this over a network via multiple protocols by supplying malicious data to affected APIs or through sandboxed Java Web Start applications and applets. Successful exploitation allows the attacker to cause a partial denial of service (availability impact). This issue was addressed in the Oracle Critical Patch Update for January 2017 (e.g., Java SE 8u121 and 7u131).

Affected products

  • Oracle Java SE 7u121, 8u112
  • Oracle Java SE Embedded 8u111
  • Oracle JRockit R28.3.12

Timeline

  • 2017-01-19: patched: Red Hat issued security updates for affected Java packages.
  • 2017-01-27: disclosed: NVD publication date.

References

Related threats