Junglewise Threat Intelligence

CVE-2017-3253: Oracle Java SE denial of service in 2D component

CVE-2017-3253 · Severity: high · CVSS 7.5 · Published 2017-01-27

Technologies: Oracle Java SE, Oracle JRockit, Oracle Java SE Embedded. Vendors: Oracle.

Executive brief

A vulnerability in the 2D graphics component of Oracle Java can allow a remote attacker to crash or freeze a Java-based application. This affects both client-side applications, like web applets, and server-side web services. An exploit could lead to a complete denial of service, disrupting business operations and application availability.

Technical details

The vulnerability is located in the 2D subcomponent of the Java Runtime Environment, specifically within the imageio PNGImageReader. The root cause involves a failure to properly honor the 'ignoreMetadata' flag when processing iTXt and zTXt chunks in PNG images. An unauthenticated attacker can exploit this by providing specially crafted data to Java APIs (e.g., via a web service) or through sandboxed Java Web Start applications and applets. Successful exploitation results in a complete denial of service (hang or crash) of the Java process. Patches were released in the January 2017 Oracle Critical Patch Update (e.g., Java SE 8u121).

Affected products

  • Oracle Java SE 6u131, 7u121, 8u112
  • Oracle Java SE Embedded 8u111
  • Oracle JRockit R28.3.12

Timeline

  • 2017-01-17: advisory: Oracle Critical Patch Update released
  • 2017-01-19: patched: Red Hat released security updates for affected Java packages
  • 2017-01-27: disclosed: NVD publication date

References

Related threats