Executive brief
A vulnerability in Oracle Java's core libraries could allow an attacker to gain unauthorized access to sensitive data. This issue primarily affects desktop users running Java applets or Web Start applications that process untrusted content from the internet. To be successful, an attacker must convince a user to interact with a malicious website or application.
Technical details
This vulnerability is a timing attack within the Elliptic Curve Digital Signature Algorithm (ECDSA) implementation in the Oracle Java SE Libraries subcomponent. An unauthenticated attacker can exploit this over a network via multiple protocols, though the attack requires human interaction (User Interaction: Required). The flaw specifically impacts Java deployments that rely on the sandbox for security, such as Java Web Start applications and applets. Successful exploitation can lead to unauthorized access to critical data or complete access to all data accessible by the Java environment. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Java SE 7u121, 8u112
- Oracle Java SE Embedded 8u111
Timeline
- 2017-01-19: patched: Red Hat released security updates addressing this vulnerability.
- 2017-01-27: disclosed: NVD published the vulnerability details.
References
- http://rhn.redhat.com/errata/RHSA-2017-0175.html
- http://rhn.redhat.com/errata/RHSA-2017-0176.html
- http://rhn.redhat.com/errata/RHSA-2017-0263.html
- http://rhn.redhat.com/errata/RHSA-2017-0336.html
- http://rhn.redhat.com/errata/RHSA-2017-0337.html
- http://rhn.redhat.com/errata/RHSA-2017-0338.html
- http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html