Executive brief
A vulnerability exists in the core libraries of Oracle Java SE and Java SE Embedded, which are used to run applications across millions of devices and web browsers. An attacker could exploit this flaw to gain unauthorized access to sensitive data on a user's system. This typically affects users running untrusted Java content from the internet, such as legacy web applets, and requires the user to interact with a malicious site or application.
Technical details
This vulnerability is a timing attack within the Digital Signature Algorithm (DSA) implementation in the Oracle Java SE Libraries subcomponent. It allows an unauthenticated attacker with network access to compromise the Java runtime environment, provided they can induce a user to interact with malicious untrusted code (such as a sandboxed Java Web Start application or applet). Successful exploitation results in unauthorized access to critical data or complete access to all data accessible by the Java process. The issue primarily impacts client-side deployments that rely on the Java sandbox for security when running untrusted code. Oracle addressed this in the January 2017 Critical Patch Update (CPU).
Affected products
- Oracle Java SE 6u131, 7u121, 8u112
- Oracle Java SE Embedded 8u111
Timeline
- 2017-01-19: patched: Red Hat issued security advisories for affected Java versions.
- 2017-01-27: disclosed: NVD published the vulnerability details.
References
- http://rhn.redhat.com/errata/RHSA-2017-0175.html
- http://rhn.redhat.com/errata/RHSA-2017-0176.html
- http://rhn.redhat.com/errata/RHSA-2017-0177.html
- http://rhn.redhat.com/errata/RHSA-2017-0180.html
- http://rhn.redhat.com/errata/RHSA-2017-0263.html
- http://rhn.redhat.com/errata/RHSA-2017-0269.html
- http://rhn.redhat.com/errata/RHSA-2017-0336.html