Executive brief
A vulnerability exists in the Networking component of Oracle Java SE and Java SE Embedded. This flaw primarily affects client-side Java deployments, such as web applets or Java Web Start applications that run untrusted code from the internet. If exploited, an attacker could gain unauthorized access to a limited portion of the data accessible by the Java application, potentially compromising sensitive information. Successful exploitation requires a user to perform a specific action, such as visiting a malicious website.
Technical details
An integer overflow vulnerability exists in the SocketOutputStream boundary check within the Networking subcomponent of Oracle Java SE. The flaw is easily exploitable by an unauthenticated attacker with network access via multiple protocols. Successful exploitation requires user interaction (UI:R), typically involving a user running a sandboxed Java Web Start application or applet that loads untrusted code. An attacker can leverage this overflow to bypass security checks and achieve unauthorized read access to a subset of data accessible to the Java runtime. This issue was addressed in the Oracle January 2017 Critical Patch Update.
Affected products
- Oracle Java SE 6u131, 7u121, 8u112
- Oracle Java SE Embedded 8u111
Timeline
- 2017-01-19: patched: Red Hat released security updates for Java 1.7 and 1.8.
- 2017-01-27: disclosed: Initial NVD publication date.
References
- http://rhn.redhat.com/errata/RHSA-2017-0175.html
- http://rhn.redhat.com/errata/RHSA-2017-0176.html
- http://rhn.redhat.com/errata/RHSA-2017-0177.html
- http://rhn.redhat.com/errata/RHSA-2017-0180.html
- http://rhn.redhat.com/errata/RHSA-2017-0263.html
- http://rhn.redhat.com/errata/RHSA-2017-0269.html
- http://rhn.redhat.com/errata/RHSA-2017-0336.html