{"cves":[{"id":"CVE-2017-10347","published":"2017-10-19T00:00:00","updated_at":"2025-08-25T22:19:29.647598+00:00","description":"\nVulnerability in the Java SE, JRockit component of Oracle Java SE\n(subcomponent: Serialization). Supported versions that are affected are\nJava SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily\nexploitable vulnerability allows unauthenticated attacker with network\naccess via multiple protocols to compromise Java SE, JRockit. Successful\nattacks of this vulnerability can result in unauthorized ability to cause a\npartial denial of service (partial DOS) of Java SE, JRockit. Note: This\nvulnerability applies to Java deployments, typically in clients running\nsandboxed Java Web Start applications or sandboxed Java applets, that load\nand run untrusted code (e.g., code that comes from the internet) and rely\non the Java sandbox for security. This vulnerability does not apply to Java\ndeployments, typically in servers, that load and run only trusted code\n(e.g., code installed by an administrator). CVSS 3.0 Base Score 5.3\n(Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","ubuntu_description":"\nGaston Traberg discovered that the Serialization component of OpenJDK\ndid not properly limit the amount of memory allocated when performing\ndeserializations in the SimpleTimeZone class. An attacker could use\nthis to cause a denial of service (memory exhaustion).","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3473-1","https://ubuntu.com/security/notices/USN-3497-1","https://www.cve.org/CVERecord?id=CVE-2017-10347"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-8":[],"icedtea-web":[],"openjdk-9":[]},"tags":{},"packages":[{"name":"icedtea-web","source":"https://ubuntu.com/security/cve?package=icedtea-web","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icedtea-web","debian":"https://tracker.debian.org/pkg/icedtea-web","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-2ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"released","description":"8u151-b12-0ubuntu0.17.10.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8u151","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u151-b12-0ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u151-b12-0ubuntu0.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.0.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-3473-1","USN-3497-1"],"notices":[{"id":"USN-3473-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-11-08T07:48:39.944652","description":"It was discovered that the Smart Card IO subsystem in OpenJDK did not\nproperly maintain state. An attacker could use this to specially construct\nan untrusted Java application or applet to gain access to a smart card,\nbypassing sandbox restrictions. (CVE-2017-10274)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10281)\n\nIt was discovered that the Remote Method Invocation (RMI) component in\nOpenJDK did not properly handle unreferenced objects. An attacker could use\nthis to specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10285)\n\nIt was discovered that the HTTPUrlConnection classes in OpenJDK did not\nproperly handle newlines. An attacker could use this to convince a Java\napplication or applet to inject headers into http requests.\n(CVE-2017-10295)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi\ndiscovered that the Serialization component of OpenJDK did not properly\nrestrict the amount of memory allocated when deserializing objects from\nJava Cryptography Extension KeyStore (JCEKS). An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10345)\n\nIt was discovered that the Hotspot component of OpenJDK did not properly\nperform loader checks when handling the invokespecial JVM instruction. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10346)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations in the SimpleTimeZone class. An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10347)\n\nIt was discovered that the Serialization component of OpenJDK did not\nproperly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10348, CVE-2017-10357)\n\nIt was discovered that the JAXP component in OpenJDK did not properly limit\nthe amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10349)\n\nIt was discovered that the JAX-WS component in OpenJDK did not properly\nlimit the amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10350)\n\nIt was discovered that the Networking component of OpenJDK did not properly\nset timeouts on FTP client actions. A remote attacker could use this to\ncause a denial of service (application hang). (CVE-2017-10355)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, Riccardo Focardi, and\nTobias Ospelt discovered that the Security component in OpenJDK did not\nsufficiently protect password-based encryption keys in key stores. An\nattacker could use this to expose sensitive information. (CVE-2017-10356)\n\nJeffrey Altman discovered that the Kerberos client implementation in\nOpenJDK incorrectly trusted unauthenticated portions of Kerberos tickets. A\nremote attacker could use this to impersonate trusted network services or\nperform other attacks. (CVE-2017-10388)\n","is_hidden":false,"release_packages":{"artful":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.17.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"}],"xenial":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"]},{"id":"USN-3497-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-11-29T07:41:06.262195","description":"It was discovered that the Smart Card IO subsystem in OpenJDK did not\nproperly maintain state. An attacker could use this to specially construct\nan untrusted Java application or applet to gain access to a smart card,\nbypassing sandbox restrictions. (CVE-2017-10274)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10281)\n\nIt was discovered that the Remote Method Invocation (RMI) component in\nOpenJDK did not properly handle unreferenced objects. An attacker could use\nthis to specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10285)\n\nIt was discovered that the HTTPUrlConnection classes in OpenJDK did not\nproperly handle newlines. An attacker could use this to convince a Java\napplication or applet to inject headers into http requests.\n(CVE-2017-10295)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi\ndiscovered that the Serialization component of OpenJDK did not properly\nrestrict the amount of memory allocated when deserializing objects from\nJava Cryptography Extension KeyStore (JCEKS). An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10345)\n\nIt was discovered that the Hotspot component of OpenJDK did not properly\nperform loader checks when handling the invokespecial JVM instruction. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10346)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations in the SimpleTimeZone class. An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10347)\n\nIt was discovered that the Serialization component of OpenJDK did not\nproperly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10348, CVE-2017-10357)\n\nIt was discovered that the JAXP component in OpenJDK did not properly limit\nthe amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10349)\n\nIt was discovered that the JAX-WS component in OpenJDK did not properly\nlimit the amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10350)\n\nIt was discovered that the Networking component of OpenJDK did not properly\nset timeouts on FTP client actions. A remote attacker could use this to\ncause a denial of service (application hang). (CVE-2017-10355)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, Riccardo Focardi, and\nTobias Ospelt discovered that the Security component in OpenJDK did not\nsufficiently protect password-based encryption keys in key stores. An\nattacker could use this to expose sensitive information. (CVE-2017-10356)\n\nJeffrey Altman discovered that the Kerberos client implementation in\nOpenJDK incorrectly trusted unauthenticated portions of Kerberos tickets. A\nremote attacker could use this to impersonate trusted network services or\nperform other attacks. (CVE-2017-10388)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-2ubuntu0.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"]}]},{"id":"CVE-2017-10346","published":"2017-10-19T00:00:00","updated_at":"2025-08-25T22:19:29.647598+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded component of Oracle Java SE\n(subcomponent: Hotspot). Supported versions that are affected are Java SE:\n6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable\nvulnerability allows unauthenticated attacker with network access via\nmultiple protocols to compromise Java SE, Java SE Embedded. Successful\nattacks require human interaction from a person other than the attacker and\nwhile the vulnerability is in Java SE, Java SE Embedded, attacks may\nsignificantly impact additional products. Successful attacks of this\nvulnerability can result in takeover of Java SE, Java SE Embedded. Note:\nThis vulnerability applies to Java deployments, typically in clients\nrunning sandboxed Java Web Start applications or sandboxed Java applets,\nthat load and run untrusted code (e.g., code that comes from the internet)\nand rely on the Java sandbox for security. This vulnerability does not\napply to Java deployments, typically in servers, that load and run only\ntrusted code (e.g., code installed by an administrator). CVSS 3.0 Base\nScore 9.6 (Confidentiality, Integrity and Availability impacts). CVSS\nVector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).","ubuntu_description":"\nIt was discovered that the Hotspot component of OpenJDK did not\nproperly perform loader checks when handling the invokespecial\nJVM instruction. An attacker could use this to specially construct\nan untrusted Java application or applet that could escape sandbox\nrestrictions.","notes":[],"codename":null,"priority":"medium","cvss3":9.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.6,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html#AppendixJAVA","https://ubuntu.com/security/notices/USN-3473-1","https://ubuntu.com/security/notices/USN-3497-1","https://www.cve.org/CVERecord?id=CVE-2017-10346"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/hotspot/rev/158904fa31b2"],"icedtea-web":[],"openjdk-9":[]},"tags":{},"packages":[{"name":"icedtea-web","source":"https://ubuntu.com/security/cve?package=icedtea-web","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icedtea-web","debian":"https://tracker.debian.org/pkg/icedtea-web","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-2ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"released","description":"8u151-b12-0ubuntu0.17.10.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8u151","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u151-b12-0ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u151-b12-0ubuntu0.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.0.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-3473-1","USN-3497-1"],"notices":[{"id":"USN-3473-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-11-08T07:48:39.944652","description":"It was discovered that the Smart Card IO subsystem in OpenJDK did not\nproperly maintain state. An attacker could use this to specially construct\nan untrusted Java application or applet to gain access to a smart card,\nbypassing sandbox restrictions. (CVE-2017-10274)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10281)\n\nIt was discovered that the Remote Method Invocation (RMI) component in\nOpenJDK did not properly handle unreferenced objects. An attacker could use\nthis to specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10285)\n\nIt was discovered that the HTTPUrlConnection classes in OpenJDK did not\nproperly handle newlines. An attacker could use this to convince a Java\napplication or applet to inject headers into http requests.\n(CVE-2017-10295)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi\ndiscovered that the Serialization component of OpenJDK did not properly\nrestrict the amount of memory allocated when deserializing objects from\nJava Cryptography Extension KeyStore (JCEKS). An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10345)\n\nIt was discovered that the Hotspot component of OpenJDK did not properly\nperform loader checks when handling the invokespecial JVM instruction. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10346)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations in the SimpleTimeZone class. An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10347)\n\nIt was discovered that the Serialization component of OpenJDK did not\nproperly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10348, CVE-2017-10357)\n\nIt was discovered that the JAXP component in OpenJDK did not properly limit\nthe amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10349)\n\nIt was discovered that the JAX-WS component in OpenJDK did not properly\nlimit the amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10350)\n\nIt was discovered that the Networking component of OpenJDK did not properly\nset timeouts on FTP client actions. A remote attacker could use this to\ncause a denial of service (application hang). (CVE-2017-10355)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, Riccardo Focardi, and\nTobias Ospelt discovered that the Security component in OpenJDK did not\nsufficiently protect password-based encryption keys in key stores. An\nattacker could use this to expose sensitive information. (CVE-2017-10356)\n\nJeffrey Altman discovered that the Kerberos client implementation in\nOpenJDK incorrectly trusted unauthenticated portions of Kerberos tickets. A\nremote attacker could use this to impersonate trusted network services or\nperform other attacks. (CVE-2017-10388)\n","is_hidden":false,"release_packages":{"artful":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.17.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"}],"xenial":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"]},{"id":"USN-3497-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-11-29T07:41:06.262195","description":"It was discovered that the Smart Card IO subsystem in OpenJDK did not\nproperly maintain state. An attacker could use this to specially construct\nan untrusted Java application or applet to gain access to a smart card,\nbypassing sandbox restrictions. (CVE-2017-10274)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10281)\n\nIt was discovered that the Remote Method Invocation (RMI) component in\nOpenJDK did not properly handle unreferenced objects. An attacker could use\nthis to specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10285)\n\nIt was discovered that the HTTPUrlConnection classes in OpenJDK did not\nproperly handle newlines. An attacker could use this to convince a Java\napplication or applet to inject headers into http requests.\n(CVE-2017-10295)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi\ndiscovered that the Serialization component of OpenJDK did not properly\nrestrict the amount of memory allocated when deserializing objects from\nJava Cryptography Extension KeyStore (JCEKS). An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10345)\n\nIt was discovered that the Hotspot component of OpenJDK did not properly\nperform loader checks when handling the invokespecial JVM instruction. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10346)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations in the SimpleTimeZone class. An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10347)\n\nIt was discovered that the Serialization component of OpenJDK did not\nproperly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10348, CVE-2017-10357)\n\nIt was discovered that the JAXP component in OpenJDK did not properly limit\nthe amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10349)\n\nIt was discovered that the JAX-WS component in OpenJDK did not properly\nlimit the amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10350)\n\nIt was discovered that the Networking component of OpenJDK did not properly\nset timeouts on FTP client actions. A remote attacker could use this to\ncause a denial of service (application hang). (CVE-2017-10355)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, Riccardo Focardi, and\nTobias Ospelt discovered that the Security component in OpenJDK did not\nsufficiently protect password-based encryption keys in key stores. An\nattacker could use this to expose sensitive information. (CVE-2017-10356)\n\nJeffrey Altman discovered that the Kerberos client implementation in\nOpenJDK incorrectly trusted unauthenticated portions of Kerberos tickets. A\nremote attacker could use this to impersonate trusted network services or\nperform other attacks. (CVE-2017-10388)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-2ubuntu0.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"]}]},{"id":"CVE-2017-10345","published":"2017-10-19T00:00:00","updated_at":"2025-08-25T22:19:29.647598+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle\nJava SE (subcomponent: Serialization). Supported versions that are affected\nare Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit:\nR28.3.15. Difficult to exploit vulnerability allows unauthenticated\nattacker with network access via multiple protocols to compromise Java SE,\nJava SE Embedded, JRockit. Successful attacks require human interaction\nfrom a person other than the attacker. Successful attacks of this\nvulnerability can result in unauthorized ability to cause a partial denial\nof service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This\nvulnerability can be exploited through sandboxed Java Web Start\napplications and sandboxed Java applets. It can also be exploited by\nsupplying data to APIs in the specified Component without using sandboxed\nJava Web Start applications or sandboxed Java applets, such as through a\nweb service. CVSS 3.0 Base Score 3.1 (Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L).","ubuntu_description":"\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo\nFocardi discovered that the Serialization component of OpenJDK did not\nproperly restrict the amount of memory allocated when deserializing\nobjects from Java Cryptography Extension KeyStore (JCEKS). An attacker\ncould use this to cause a denial of service (memory exhaustion).","notes":[],"codename":null,"priority":"medium","cvss3":3.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html#AppendixJAVA","https://ubuntu.com/security/notices/USN-3473-1","https://ubuntu.com/security/notices/USN-3497-1","https://www.cve.org/CVERecord?id=CVE-2017-10345"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-10345"],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-8":[],"icedtea-web":[],"openjdk-9":[]},"tags":{},"packages":[{"name":"icedtea-web","source":"https://ubuntu.com/security/cve?package=icedtea-web","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icedtea-web","debian":"https://tracker.debian.org/pkg/icedtea-web","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-2ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"released","description":"8u151-b12-0ubuntu0.17.10.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8u151","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u151-b12-0ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u151-b12-0ubuntu0.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.0.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-3473-1","USN-3497-1"],"notices":[{"id":"USN-3473-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-11-08T07:48:39.944652","description":"It was discovered that the Smart Card IO subsystem in OpenJDK did not\nproperly maintain state. An attacker could use this to specially construct\nan untrusted Java application or applet to gain access to a smart card,\nbypassing sandbox restrictions. (CVE-2017-10274)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10281)\n\nIt was discovered that the Remote Method Invocation (RMI) component in\nOpenJDK did not properly handle unreferenced objects. An attacker could use\nthis to specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10285)\n\nIt was discovered that the HTTPUrlConnection classes in OpenJDK did not\nproperly handle newlines. An attacker could use this to convince a Java\napplication or applet to inject headers into http requests.\n(CVE-2017-10295)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi\ndiscovered that the Serialization component of OpenJDK did not properly\nrestrict the amount of memory allocated when deserializing objects from\nJava Cryptography Extension KeyStore (JCEKS). An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10345)\n\nIt was discovered that the Hotspot component of OpenJDK did not properly\nperform loader checks when handling the invokespecial JVM instruction. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10346)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations in the SimpleTimeZone class. An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10347)\n\nIt was discovered that the Serialization component of OpenJDK did not\nproperly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10348, CVE-2017-10357)\n\nIt was discovered that the JAXP component in OpenJDK did not properly limit\nthe amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10349)\n\nIt was discovered that the JAX-WS component in OpenJDK did not properly\nlimit the amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10350)\n\nIt was discovered that the Networking component of OpenJDK did not properly\nset timeouts on FTP client actions. A remote attacker could use this to\ncause a denial of service (application hang). (CVE-2017-10355)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, Riccardo Focardi, and\nTobias Ospelt discovered that the Security component in OpenJDK did not\nsufficiently protect password-based encryption keys in key stores. An\nattacker could use this to expose sensitive information. (CVE-2017-10356)\n\nJeffrey Altman discovered that the Kerberos client implementation in\nOpenJDK incorrectly trusted unauthenticated portions of Kerberos tickets. A\nremote attacker could use this to impersonate trusted network services or\nperform other attacks. (CVE-2017-10388)\n","is_hidden":false,"release_packages":{"artful":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.17.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"}],"xenial":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"]},{"id":"USN-3497-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-11-29T07:41:06.262195","description":"It was discovered that the Smart Card IO subsystem in OpenJDK did not\nproperly maintain state. An attacker could use this to specially construct\nan untrusted Java application or applet to gain access to a smart card,\nbypassing sandbox restrictions. (CVE-2017-10274)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10281)\n\nIt was discovered that the Remote Method Invocation (RMI) component in\nOpenJDK did not properly handle unreferenced objects. An attacker could use\nthis to specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10285)\n\nIt was discovered that the HTTPUrlConnection classes in OpenJDK did not\nproperly handle newlines. An attacker could use this to convince a Java\napplication or applet to inject headers into http requests.\n(CVE-2017-10295)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi\ndiscovered that the Serialization component of OpenJDK did not properly\nrestrict the amount of memory allocated when deserializing objects from\nJava Cryptography Extension KeyStore (JCEKS). An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10345)\n\nIt was discovered that the Hotspot component of OpenJDK did not properly\nperform loader checks when handling the invokespecial JVM instruction. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10346)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations in the SimpleTimeZone class. An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10347)\n\nIt was discovered that the Serialization component of OpenJDK did not\nproperly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10348, CVE-2017-10357)\n\nIt was discovered that the JAXP component in OpenJDK did not properly limit\nthe amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10349)\n\nIt was discovered that the JAX-WS component in OpenJDK did not properly\nlimit the amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10350)\n\nIt was discovered that the Networking component of OpenJDK did not properly\nset timeouts on FTP client actions. A remote attacker could use this to\ncause a denial of service (application hang). (CVE-2017-10355)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, Riccardo Focardi, and\nTobias Ospelt discovered that the Security component in OpenJDK did not\nsufficiently protect password-based encryption keys in key stores. An\nattacker could use this to expose sensitive information. (CVE-2017-10356)\n\nJeffrey Altman discovered that the Kerberos client implementation in\nOpenJDK incorrectly trusted unauthenticated portions of Kerberos tickets. A\nremote attacker could use this to impersonate trusted network services or\nperform other attacks. (CVE-2017-10388)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-2ubuntu0.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"]}]},{"id":"CVE-2017-10295","published":"2017-10-19T00:00:00","updated_at":"2025-08-25T22:19:29.647598+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle\nJava SE (subcomponent: Networking). Supported versions that are affected\nare Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit:\nR28.3.15. Difficult to exploit vulnerability allows unauthenticated\nattacker with network access via HTTP to compromise Java SE, Java SE\nEmbedded, JRockit. While the vulnerability is in Java SE, Java SE Embedded,\nJRockit, attacks may significantly impact additional products. Successful\nattacks of this vulnerability can result in unauthorized update, insert or\ndelete access to some of Java SE, Java SE Embedded, JRockit accessible\ndata. Note: This vulnerability can be exploited through sandboxed Java Web\nStart applications and sandboxed Java applets. It can also be exploited by\nsupplying data to APIs in the specified Component without using sandboxed\nJava Web Start applications or sandboxed Java applets, such as through a\nweb service. CVSS 3.0 Base Score 4.0 (Integrity impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N).","ubuntu_description":"\nIt was discovered that the HTTPUrlConnection classes in OpenJDK did\nnot properly handle newlines. An attacker could use this to convince\na Java application or applet to inject headers into http requests.","notes":[],"codename":null,"priority":"medium","cvss3":4.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3473-1","https://ubuntu.com/security/notices/USN-3497-1","https://www.cve.org/CVERecord?id=CVE-2017-10295"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/0cb8f2bf8651"],"icedtea-web":[],"openjdk-9":[]},"tags":{},"packages":[{"name":"icedtea-web","source":"https://ubuntu.com/security/cve?package=icedtea-web","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icedtea-web","debian":"https://tracker.debian.org/pkg/icedtea-web","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-2ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"released","description":"8u151-b12-0ubuntu0.17.10.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8u151","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u151-b12-0ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u151-b12-0ubuntu0.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.0.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-3473-1","USN-3497-1"],"notices":[{"id":"USN-3473-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-11-08T07:48:39.944652","description":"It was discovered that the Smart Card IO subsystem in OpenJDK did not\nproperly maintain state. An attacker could use this to specially construct\nan untrusted Java application or applet to gain access to a smart card,\nbypassing sandbox restrictions. (CVE-2017-10274)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10281)\n\nIt was discovered that the Remote Method Invocation (RMI) component in\nOpenJDK did not properly handle unreferenced objects. An attacker could use\nthis to specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10285)\n\nIt was discovered that the HTTPUrlConnection classes in OpenJDK did not\nproperly handle newlines. An attacker could use this to convince a Java\napplication or applet to inject headers into http requests.\n(CVE-2017-10295)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi\ndiscovered that the Serialization component of OpenJDK did not properly\nrestrict the amount of memory allocated when deserializing objects from\nJava Cryptography Extension KeyStore (JCEKS). An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10345)\n\nIt was discovered that the Hotspot component of OpenJDK did not properly\nperform loader checks when handling the invokespecial JVM instruction. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10346)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations in the SimpleTimeZone class. An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10347)\n\nIt was discovered that the Serialization component of OpenJDK did not\nproperly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10348, CVE-2017-10357)\n\nIt was discovered that the JAXP component in OpenJDK did not properly limit\nthe amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10349)\n\nIt was discovered that the JAX-WS component in OpenJDK did not properly\nlimit the amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10350)\n\nIt was discovered that the Networking component of OpenJDK did not properly\nset timeouts on FTP client actions. A remote attacker could use this to\ncause a denial of service (application hang). (CVE-2017-10355)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, Riccardo Focardi, and\nTobias Ospelt discovered that the Security component in OpenJDK did not\nsufficiently protect password-based encryption keys in key stores. An\nattacker could use this to expose sensitive information. (CVE-2017-10356)\n\nJeffrey Altman discovered that the Kerberos client implementation in\nOpenJDK incorrectly trusted unauthenticated portions of Kerberos tickets. A\nremote attacker could use this to impersonate trusted network services or\nperform other attacks. (CVE-2017-10388)\n","is_hidden":false,"release_packages":{"artful":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.17.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"}],"xenial":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"]},{"id":"USN-3497-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-11-29T07:41:06.262195","description":"It was discovered that the Smart Card IO subsystem in OpenJDK did not\nproperly maintain state. An attacker could use this to specially construct\nan untrusted Java application or applet to gain access to a smart card,\nbypassing sandbox restrictions. (CVE-2017-10274)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10281)\n\nIt was discovered that the Remote Method Invocation (RMI) component in\nOpenJDK did not properly handle unreferenced objects. An attacker could use\nthis to specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10285)\n\nIt was discovered that the HTTPUrlConnection classes in OpenJDK did not\nproperly handle newlines. An attacker could use this to convince a Java\napplication or applet to inject headers into http requests.\n(CVE-2017-10295)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi\ndiscovered that the Serialization component of OpenJDK did not properly\nrestrict the amount of memory allocated when deserializing objects from\nJava Cryptography Extension KeyStore (JCEKS). An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10345)\n\nIt was discovered that the Hotspot component of OpenJDK did not properly\nperform loader checks when handling the invokespecial JVM instruction. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10346)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations in the SimpleTimeZone class. An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10347)\n\nIt was discovered that the Serialization component of OpenJDK did not\nproperly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10348, CVE-2017-10357)\n\nIt was discovered that the JAXP component in OpenJDK did not properly limit\nthe amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10349)\n\nIt was discovered that the JAX-WS component in OpenJDK did not properly\nlimit the amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10350)\n\nIt was discovered that the Networking component of OpenJDK did not properly\nset timeouts on FTP client actions. A remote attacker could use this to\ncause a denial of service (application hang). (CVE-2017-10355)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, Riccardo Focardi, and\nTobias Ospelt discovered that the Security component in OpenJDK did not\nsufficiently protect password-based encryption keys in key stores. An\nattacker could use this to expose sensitive information. (CVE-2017-10356)\n\nJeffrey Altman discovered that the Kerberos client implementation in\nOpenJDK incorrectly trusted unauthenticated portions of Kerberos tickets. A\nremote attacker could use this to impersonate trusted network services or\nperform other attacks. (CVE-2017-10388)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-2ubuntu0.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"]}]},{"id":"CVE-2017-10285","published":"2017-10-19T00:00:00","updated_at":"2025-08-25T22:19:24.136139+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded component of Oracle Java SE\n(subcomponent: RMI). Supported versions that are affected are Java SE:\n6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable\nvulnerability allows unauthenticated attacker with network access via\nmultiple protocols to compromise Java SE, Java SE Embedded. Successful\nattacks require human interaction from a person other than the attacker and\nwhile the vulnerability is in Java SE, Java SE Embedded, attacks may\nsignificantly impact additional products. Successful attacks of this\nvulnerability can result in takeover of Java SE, Java SE Embedded. Note:\nThis vulnerability applies to Java deployments, typically in clients\nrunning sandboxed Java Web Start applications or sandboxed Java applets,\nthat load and run untrusted code (e.g., code that comes from the internet)\nand rely on the Java sandbox for security. This vulnerability does not\napply to Java deployments, typically in servers, that load and run only\ntrusted code (e.g., code installed by an administrator). CVSS 3.0 Base\nScore 9.6 (Confidentiality, Integrity and Availability impacts). CVSS\nVector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).","ubuntu_description":"\nIt was discovered that the Remote Method Invocation (RMI) component\nin OpenJDK did not properly handle unreferenced objects. An attacker\ncould use this to specially construct an untrusted Java application\nor applet that could escape sandbox restrictions.","notes":[],"codename":null,"priority":"medium","cvss3":9.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.6,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3473-1","https://ubuntu.com/security/notices/USN-3497-1","https://www.cve.org/CVERecord?id=CVE-2017-10285"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-8":[],"icedtea-web":[],"openjdk-9":[]},"tags":{},"packages":[{"name":"icedtea-web","source":"https://ubuntu.com/security/cve?package=icedtea-web","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icedtea-web","debian":"https://tracker.debian.org/pkg/icedtea-web","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-2ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"released","description":"8u151-b12-0ubuntu0.17.10.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8u151","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u151-b12-0ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u151-b12-0ubuntu0.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.0.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-3473-1","USN-3497-1"],"notices":[{"id":"USN-3473-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-11-08T07:48:39.944652","description":"It was discovered that the Smart Card IO subsystem in OpenJDK did not\nproperly maintain state. An attacker could use this to specially construct\nan untrusted Java application or applet to gain access to a smart card,\nbypassing sandbox restrictions. (CVE-2017-10274)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10281)\n\nIt was discovered that the Remote Method Invocation (RMI) component in\nOpenJDK did not properly handle unreferenced objects. An attacker could use\nthis to specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10285)\n\nIt was discovered that the HTTPUrlConnection classes in OpenJDK did not\nproperly handle newlines. An attacker could use this to convince a Java\napplication or applet to inject headers into http requests.\n(CVE-2017-10295)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi\ndiscovered that the Serialization component of OpenJDK did not properly\nrestrict the amount of memory allocated when deserializing objects from\nJava Cryptography Extension KeyStore (JCEKS). An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10345)\n\nIt was discovered that the Hotspot component of OpenJDK did not properly\nperform loader checks when handling the invokespecial JVM instruction. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10346)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations in the SimpleTimeZone class. An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10347)\n\nIt was discovered that the Serialization component of OpenJDK did not\nproperly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10348, CVE-2017-10357)\n\nIt was discovered that the JAXP component in OpenJDK did not properly limit\nthe amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10349)\n\nIt was discovered that the JAX-WS component in OpenJDK did not properly\nlimit the amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10350)\n\nIt was discovered that the Networking component of OpenJDK did not properly\nset timeouts on FTP client actions. A remote attacker could use this to\ncause a denial of service (application hang). (CVE-2017-10355)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, Riccardo Focardi, and\nTobias Ospelt discovered that the Security component in OpenJDK did not\nsufficiently protect password-based encryption keys in key stores. An\nattacker could use this to expose sensitive information. (CVE-2017-10356)\n\nJeffrey Altman discovered that the Kerberos client implementation in\nOpenJDK incorrectly trusted unauthenticated portions of Kerberos tickets. A\nremote attacker could use this to impersonate trusted network services or\nperform other attacks. (CVE-2017-10388)\n","is_hidden":false,"release_packages":{"artful":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.17.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"}],"xenial":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"]},{"id":"USN-3497-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-11-29T07:41:06.262195","description":"It was discovered that the Smart Card IO subsystem in OpenJDK did not\nproperly maintain state. An attacker could use this to specially construct\nan untrusted Java application or applet to gain access to a smart card,\nbypassing sandbox restrictions. (CVE-2017-10274)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10281)\n\nIt was discovered that the Remote Method Invocation (RMI) component in\nOpenJDK did not properly handle unreferenced objects. An attacker could use\nthis to specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10285)\n\nIt was discovered that the HTTPUrlConnection classes in OpenJDK did not\nproperly handle newlines. An attacker could use this to convince a Java\napplication or applet to inject headers into http requests.\n(CVE-2017-10295)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi\ndiscovered that the Serialization component of OpenJDK did not properly\nrestrict the amount of memory allocated when deserializing objects from\nJava Cryptography Extension KeyStore (JCEKS). An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10345)\n\nIt was discovered that the Hotspot component of OpenJDK did not properly\nperform loader checks when handling the invokespecial JVM instruction. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10346)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations in the SimpleTimeZone class. An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10347)\n\nIt was discovered that the Serialization component of OpenJDK did not\nproperly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10348, CVE-2017-10357)\n\nIt was discovered that the JAXP component in OpenJDK did not properly limit\nthe amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10349)\n\nIt was discovered that the JAX-WS component in OpenJDK did not properly\nlimit the amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10350)\n\nIt was discovered that the Networking component of OpenJDK did not properly\nset timeouts on FTP client actions. A remote attacker could use this to\ncause a denial of service (application hang). (CVE-2017-10355)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, Riccardo Focardi, and\nTobias Ospelt discovered that the Security component in OpenJDK did not\nsufficiently protect password-based encryption keys in key stores. An\nattacker could use this to expose sensitive information. (CVE-2017-10356)\n\nJeffrey Altman discovered that the Kerberos client implementation in\nOpenJDK incorrectly trusted unauthenticated portions of Kerberos tickets. A\nremote attacker could use this to impersonate trusted network services or\nperform other attacks. (CVE-2017-10388)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-2ubuntu0.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"]}]},{"id":"CVE-2017-10281","published":"2017-10-19T00:00:00","updated_at":"2025-08-25T22:19:24.136139+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle\nJava SE (subcomponent: Serialization). Supported versions that are affected\nare Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit:\nR28.3.15. Easily exploitable vulnerability allows unauthenticated attacker\nwith network access via multiple protocols to compromise Java SE, Java SE\nEmbedded, JRockit. Successful attacks of this vulnerability can result in\nunauthorized ability to cause a partial denial of service (partial DOS) of\nJava SE, Java SE Embedded, JRockit. Note: This vulnerability can be\nexploited through sandboxed Java Web Start applications and sandboxed Java\napplets. It can also be exploited by supplying data to APIs in the\nspecified Component without using sandboxed Java Web Start applications or\nsandboxed Java applets, such as through a web service. CVSS 3.0 Base Score\n5.3 (Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","ubuntu_description":"\nGaston Traberg discovered that the Serialization component of OpenJDK\ndid not properly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of\nservice (memory exhaustion).","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3473-1","https://ubuntu.com/security/notices/USN-3497-1","https://www.cve.org/CVERecord?id=CVE-2017-10281"],"bugs":[""],"patches":{"openjdk-6":[],"openjdk-7":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/4b8d4f91a480"],"icedtea-web":[],"openjdk-9":[]},"tags":{},"packages":[{"name":"icedtea-web","source":"https://ubuntu.com/security/cve?package=icedtea-web","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icedtea-web","debian":"https://tracker.debian.org/pkg/icedtea-web","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]},{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-2ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"released","description":"8u151-b12-0ubuntu0.17.10.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8u151","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u151-b12-0ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u151-b12-0ubuntu0.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.0.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-3473-1","USN-3497-1"],"notices":[{"id":"USN-3473-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-11-08T07:48:39.944652","description":"It was discovered that the Smart Card IO subsystem in OpenJDK did not\nproperly maintain state. An attacker could use this to specially construct\nan untrusted Java application or applet to gain access to a smart card,\nbypassing sandbox restrictions. (CVE-2017-10274)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10281)\n\nIt was discovered that the Remote Method Invocation (RMI) component in\nOpenJDK did not properly handle unreferenced objects. An attacker could use\nthis to specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10285)\n\nIt was discovered that the HTTPUrlConnection classes in OpenJDK did not\nproperly handle newlines. An attacker could use this to convince a Java\napplication or applet to inject headers into http requests.\n(CVE-2017-10295)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi\ndiscovered that the Serialization component of OpenJDK did not properly\nrestrict the amount of memory allocated when deserializing objects from\nJava Cryptography Extension KeyStore (JCEKS). An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10345)\n\nIt was discovered that the Hotspot component of OpenJDK did not properly\nperform loader checks when handling the invokespecial JVM instruction. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10346)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations in the SimpleTimeZone class. An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10347)\n\nIt was discovered that the Serialization component of OpenJDK did not\nproperly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10348, CVE-2017-10357)\n\nIt was discovered that the JAXP component in OpenJDK did not properly limit\nthe amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10349)\n\nIt was discovered that the JAX-WS component in OpenJDK did not properly\nlimit the amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10350)\n\nIt was discovered that the Networking component of OpenJDK did not properly\nset timeouts on FTP client actions. A remote attacker could use this to\ncause a denial of service (application hang). (CVE-2017-10355)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, Riccardo Focardi, and\nTobias Ospelt discovered that the Security component in OpenJDK did not\nsufficiently protect password-based encryption keys in key stores. An\nattacker could use this to expose sensitive information. (CVE-2017-10356)\n\nJeffrey Altman discovered that the Kerberos client implementation in\nOpenJDK incorrectly trusted unauthenticated portions of Kerberos tickets. A\nremote attacker could use this to impersonate trusted network services or\nperform other attacks. (CVE-2017-10388)\n","is_hidden":false,"release_packages":{"artful":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.17.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"}],"xenial":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"]},{"id":"USN-3497-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-11-29T07:41:06.262195","description":"It was discovered that the Smart Card IO subsystem in OpenJDK did not\nproperly maintain state. An attacker could use this to specially construct\nan untrusted Java application or applet to gain access to a smart card,\nbypassing sandbox restrictions. (CVE-2017-10274)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10281)\n\nIt was discovered that the Remote Method Invocation (RMI) component in\nOpenJDK did not properly handle unreferenced objects. An attacker could use\nthis to specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10285)\n\nIt was discovered that the HTTPUrlConnection classes in OpenJDK did not\nproperly handle newlines. An attacker could use this to convince a Java\napplication or applet to inject headers into http requests.\n(CVE-2017-10295)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi\ndiscovered that the Serialization component of OpenJDK did not properly\nrestrict the amount of memory allocated when deserializing objects from\nJava Cryptography Extension KeyStore (JCEKS). An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10345)\n\nIt was discovered that the Hotspot component of OpenJDK did not properly\nperform loader checks when handling the invokespecial JVM instruction. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10346)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations in the SimpleTimeZone class. An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10347)\n\nIt was discovered that the Serialization component of OpenJDK did not\nproperly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10348, CVE-2017-10357)\n\nIt was discovered that the JAXP component in OpenJDK did not properly limit\nthe amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10349)\n\nIt was discovered that the JAX-WS component in OpenJDK did not properly\nlimit the amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10350)\n\nIt was discovered that the Networking component of OpenJDK did not properly\nset timeouts on FTP client actions. A remote attacker could use this to\ncause a denial of service (application hang). (CVE-2017-10355)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, Riccardo Focardi, and\nTobias Ospelt discovered that the Security component in OpenJDK did not\nsufficiently protect password-based encryption keys in key stores. An\nattacker could use this to expose sensitive information. (CVE-2017-10356)\n\nJeffrey Altman discovered that the Kerberos client implementation in\nOpenJDK incorrectly trusted unauthenticated portions of Kerberos tickets. A\nremote attacker could use this to impersonate trusted network services or\nperform other attacks. (CVE-2017-10388)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-2ubuntu0.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"]}]},{"id":"CVE-2017-10274","published":"2017-10-19T00:00:00","updated_at":"2025-08-25T22:19:24.136139+00:00","description":"\nVulnerability in the Java SE component of Oracle Java SE (subcomponent:\nSmart Card IO). Supported versions that are affected are Java SE: 6u161,\n7u151, 8u144 and 9. Difficult to exploit vulnerability allows\nunauthenticated attacker with network access via multiple protocols to\ncompromise Java SE. Successful attacks require human interaction from a\nperson other than the attacker. Successful attacks of this vulnerability\ncan result in unauthorized creation, deletion or modification access to\ncritical data or all Java SE accessible data as well as unauthorized access\nto critical data or complete access to all Java SE accessible data. Note:\nThis vulnerability applies to Java deployments, typically in clients\nrunning sandboxed Java Web Start applications or sandboxed Java applets,\nthat load and run untrusted code (e.g., code that comes from the internet)\nand rely on the Java sandbox for security. This vulnerability does not\napply to Java deployments, typically in servers, that load and run only\ntrusted code (e.g., code installed by an administrator). CVSS 3.0 Base\nScore 6.8 (Confidentiality and Integrity impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).","ubuntu_description":"\nIt was discovered that the Smart Card IO subsystem in OpenJDK did\nnot properly maintain state. An attacker could use this to specially\nconstruct an untrusted Java application or applet to gain access to\na smart card, bypassing sandbox restrictions.","notes":[],"codename":null,"priority":"medium","cvss3":6.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3473-1","https://ubuntu.com/security/notices/USN-3497-1","https://www.cve.org/CVERecord?id=CVE-2017-10274"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[],"openjdk-9":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/8913fd33ceee"]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6u161","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-2ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7u151","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"released","description":"8u151-b12-0ubuntu0.17.10.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8u144","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u151-b12-0ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u151-b12-0ubuntu0.17.04.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u151-b12-1","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3473-1","USN-3497-1"],"notices":[{"id":"USN-3473-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-11-08T07:48:39.944652","description":"It was discovered that the Smart Card IO subsystem in OpenJDK did not\nproperly maintain state. An attacker could use this to specially construct\nan untrusted Java application or applet to gain access to a smart card,\nbypassing sandbox restrictions. (CVE-2017-10274)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10281)\n\nIt was discovered that the Remote Method Invocation (RMI) component in\nOpenJDK did not properly handle unreferenced objects. An attacker could use\nthis to specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10285)\n\nIt was discovered that the HTTPUrlConnection classes in OpenJDK did not\nproperly handle newlines. An attacker could use this to convince a Java\napplication or applet to inject headers into http requests.\n(CVE-2017-10295)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi\ndiscovered that the Serialization component of OpenJDK did not properly\nrestrict the amount of memory allocated when deserializing objects from\nJava Cryptography Extension KeyStore (JCEKS). An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10345)\n\nIt was discovered that the Hotspot component of OpenJDK did not properly\nperform loader checks when handling the invokespecial JVM instruction. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10346)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations in the SimpleTimeZone class. An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10347)\n\nIt was discovered that the Serialization component of OpenJDK did not\nproperly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10348, CVE-2017-10357)\n\nIt was discovered that the JAXP component in OpenJDK did not properly limit\nthe amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10349)\n\nIt was discovered that the JAX-WS component in OpenJDK did not properly\nlimit the amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10350)\n\nIt was discovered that the Networking component of OpenJDK did not properly\nset timeouts on FTP client actions. A remote attacker could use this to\ncause a denial of service (application hang). (CVE-2017-10355)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, Riccardo Focardi, and\nTobias Ospelt discovered that the Security component in OpenJDK did not\nsufficiently protect password-based encryption keys in key stores. An\nattacker could use this to expose sensitive information. (CVE-2017-10356)\n\nJeffrey Altman discovered that the Kerberos client implementation in\nOpenJDK incorrectly trusted unauthenticated portions of Kerberos tickets. A\nremote attacker could use this to impersonate trusted network services or\nperform other attacks. (CVE-2017-10388)\n","is_hidden":false,"release_packages":{"artful":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.17.10.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.17.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.10.2"}],"xenial":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u151-b12-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u151-b12-0ubuntu0.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u151-b12-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u151-b12-0ubuntu0.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"]},{"id":"USN-3497-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-11-29T07:41:06.262195","description":"It was discovered that the Smart Card IO subsystem in OpenJDK did not\nproperly maintain state. An attacker could use this to specially construct\nan untrusted Java application or applet to gain access to a smart card,\nbypassing sandbox restrictions. (CVE-2017-10274)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10281)\n\nIt was discovered that the Remote Method Invocation (RMI) component in\nOpenJDK did not properly handle unreferenced objects. An attacker could use\nthis to specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10285)\n\nIt was discovered that the HTTPUrlConnection classes in OpenJDK did not\nproperly handle newlines. An attacker could use this to convince a Java\napplication or applet to inject headers into http requests.\n(CVE-2017-10295)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi\ndiscovered that the Serialization component of OpenJDK did not properly\nrestrict the amount of memory allocated when deserializing objects from\nJava Cryptography Extension KeyStore (JCEKS). An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10345)\n\nIt was discovered that the Hotspot component of OpenJDK did not properly\nperform loader checks when handling the invokespecial JVM instruction. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10346)\n\nGaston Traberg discovered that the Serialization component of OpenJDK did\nnot properly limit the amount of memory allocated when performing\ndeserializations in the SimpleTimeZone class. An attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2017-10347)\n\nIt was discovered that the Serialization component of OpenJDK did not\nproperly limit the amount of memory allocated when performing\ndeserializations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2017-10348, CVE-2017-10357)\n\nIt was discovered that the JAXP component in OpenJDK did not properly limit\nthe amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10349)\n\nIt was discovered that the JAX-WS component in OpenJDK did not properly\nlimit the amount of memory allocated when performing deserializations. An\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-10350)\n\nIt was discovered that the Networking component of OpenJDK did not properly\nset timeouts on FTP client actions. A remote attacker could use this to\ncause a denial of service (application hang). (CVE-2017-10355)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, Riccardo Focardi, and\nTobias Ospelt discovered that the Security component in OpenJDK did not\nsufficiently protect password-based encryption keys in key stores. An\nattacker could use this to expose sensitive information. (CVE-2017-10356)\n\nJeffrey Altman discovered that the Kerberos client implementation in\nOpenJDK incorrectly trusted unauthenticated portions of Kerberos tickets. A\nremote attacker could use this to impersonate trusted network services or\nperform other attacks. (CVE-2017-10388)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-2ubuntu0.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-2ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-2ubuntu0.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10274","CVE-2017-10281","CVE-2017-10285","CVE-2017-10295","CVE-2017-10345","CVE-2017-10346","CVE-2017-10347","CVE-2017-10348","CVE-2017-10349","CVE-2017-10350","CVE-2017-10355","CVE-2017-10356","CVE-2017-10357","CVE-2017-10388"]}]},{"id":"CVE-2017-15602","published":"2017-10-18T21:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nIn GNU Libextractor 1.4, there is an integer signedness error for the chunk\nsize in the EXTRACTOR_nsfe_extract_method function in\nplugins/nsfe_extractor.c, leading to an infinite loop for a crafted size.","ubuntu_description":"\nIt was discovered that Libextractor incorrectly handled integers. An\nattacker could possibly use this issue to cause a denial of service.","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00005.html","https://ftp.gnu.org/gnu/libextractor/libextractor-1.6.tar.gz","https://ubuntu.com/security/notices/USN-4641-1","https://www.cve.org/CVERecord?id=CVE-2017-15602"],"bugs":[""],"patches":{"libextractor":[]},"tags":{},"packages":[{"name":"libextractor","source":"https://ubuntu.com/security/cve?package=libextractor","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libextractor","debian":"https://tracker.debian.org/pkg/libextractor","statuses":[{"release_codename":"jammy","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.3-4+deb9u1, 1:1.6-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:1.3-4+deb9u3build0.16.04.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-4641-1"],"notices":[{"id":"USN-4641-1","title":"libextractor vulnerabilities","summary":"Several security issues were fixed in libextractor.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-11-23T18:02:19.307565","description":"It was discovered that Libextractor incorrectly handled zero sample rate.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2017-15266)\n\nIt was discovered that Libextractor incorrectly handled certain FLAC\nmetadata. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2017-15267)\n\nIt was discovered that Libextractor incorrectly handled certain specially\ncrafted files. An attacker could possibly use this issue to cause a denial\nof service. (CVE-2017-15600, CVE-2018-16430, CVE-2018-20430)\n\nIt was discovered that Libextractor incorrectly handled certain inputs. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2017-15601)\n\nIt was discovered that Libextractor incorrectly handled integers. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2017-15602)\n\nIt was discovered that Libextractore incorrectly handled certain crafted\nfiles. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2017-15922)\n\nIt was discovered tha Libextractor incorrectly handled certain files. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2017-17440)\n\nIt was discovered that Libextractor incorrectly handled certain malformed\nfiles. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2018-14346)\n\nIt was discovered that Libextractor incorrectly handled malformed files. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2018-14347)\n\nIt was discovered that Libextractor incorrectly handled metadata. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2018-20431)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"libextractor","version":"1:1.3-4+deb9u3build0.16.04.1","description":"library used to extract metadata from files","is_source":true},{"name":"extract","version":"1:1.3-4+deb9u3build0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libextractor","version_link":"https://launchpad.net/ubuntu/+source/libextractor/1:1.3-4+deb9u3build0.16.04.1","pocket":"security"},{"name":"libextractor-dev","version":"1:1.3-4+deb9u3build0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libextractor","version_link":"https://launchpad.net/ubuntu/+source/libextractor/1:1.3-4+deb9u3build0.16.04.1","pocket":"security"},{"name":"libextractor3","version":"1:1.3-4+deb9u3build0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libextractor","version_link":"https://launchpad.net/ubuntu/+source/libextractor/1:1.3-4+deb9u3build0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-14346","CVE-2018-16430","CVE-2017-15266","CVE-2017-15601","CVE-2017-15602","CVE-2018-14347","CVE-2017-15922","CVE-2018-20431","CVE-2017-15600","CVE-2017-17440","CVE-2017-15267","CVE-2018-20430"]}]},{"id":"CVE-2017-15601","published":"2017-10-18T21:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nIn GNU Libextractor 1.4, there is a heap-based buffer overflow in the\nEXTRACTOR_png_extract_method function in plugins/png_extractor.c, related\nto processiTXt and stndup.","ubuntu_description":"\nIt was discovered that Libextractor incorrectly handled certain inputs.\nAn attacker could possibly use this issue to cause a denial of service.","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00006.html","https://ftp.gnu.org/gnu/libextractor/libextractor-1.6.tar.gz","https://ubuntu.com/security/notices/USN-4641-1","https://www.cve.org/CVERecord?id=CVE-2017-15601"],"bugs":[""],"patches":{"libextractor":[]},"tags":{},"packages":[{"name":"libextractor","source":"https://ubuntu.com/security/cve?package=libextractor","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libextractor","debian":"https://tracker.debian.org/pkg/libextractor","statuses":[{"release_codename":"xenial","status":"released","description":"1:1.3-4+deb9u3build0.16.04.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.3-4+deb9u1, 1:1.6-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-4641-1"],"notices":[{"id":"USN-4641-1","title":"libextractor vulnerabilities","summary":"Several security issues were fixed in libextractor.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-11-23T18:02:19.307565","description":"It was discovered that Libextractor incorrectly handled zero sample rate.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2017-15266)\n\nIt was discovered that Libextractor incorrectly handled certain FLAC\nmetadata. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2017-15267)\n\nIt was discovered that Libextractor incorrectly handled certain specially\ncrafted files. An attacker could possibly use this issue to cause a denial\nof service. (CVE-2017-15600, CVE-2018-16430, CVE-2018-20430)\n\nIt was discovered that Libextractor incorrectly handled certain inputs. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2017-15601)\n\nIt was discovered that Libextractor incorrectly handled integers. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2017-15602)\n\nIt was discovered that Libextractore incorrectly handled certain crafted\nfiles. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2017-15922)\n\nIt was discovered tha Libextractor incorrectly handled certain files. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2017-17440)\n\nIt was discovered that Libextractor incorrectly handled certain malformed\nfiles. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2018-14346)\n\nIt was discovered that Libextractor incorrectly handled malformed files. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2018-14347)\n\nIt was discovered that Libextractor incorrectly handled metadata. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2018-20431)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"libextractor","version":"1:1.3-4+deb9u3build0.16.04.1","description":"library used to extract metadata from files","is_source":true},{"name":"extract","version":"1:1.3-4+deb9u3build0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libextractor","version_link":"https://launchpad.net/ubuntu/+source/libextractor/1:1.3-4+deb9u3build0.16.04.1","pocket":"security"},{"name":"libextractor-dev","version":"1:1.3-4+deb9u3build0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libextractor","version_link":"https://launchpad.net/ubuntu/+source/libextractor/1:1.3-4+deb9u3build0.16.04.1","pocket":"security"},{"name":"libextractor3","version":"1:1.3-4+deb9u3build0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libextractor","version_link":"https://launchpad.net/ubuntu/+source/libextractor/1:1.3-4+deb9u3build0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-14346","CVE-2018-16430","CVE-2017-15266","CVE-2017-15601","CVE-2017-15602","CVE-2018-14347","CVE-2017-15922","CVE-2018-20431","CVE-2017-15600","CVE-2017-17440","CVE-2017-15267","CVE-2018-20430"]}]},{"id":"CVE-2017-15600","published":"2017-10-18T21:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nIn GNU Libextractor 1.4, there is a NULL Pointer Dereference in the\nEXTRACTOR_nsf_extract_method function of plugins/nsf_extractor.c.","ubuntu_description":"\nIt was discovered that Libextractor incorrectly handled certain specially\ncrafted files. An attacker could possibly use this issue to cause a\ndenial of service.","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://lists.gnu.org/archive/html/bug-libextractor/2017-10/msg00004.html","https://ftp.gnu.org/gnu/libextractor/libextractor-1.6.tar.gz","https://ubuntu.com/security/notices/USN-4641-1","https://www.cve.org/CVERecord?id=CVE-2017-15600"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1501695"],"patches":{"libextractor":[]},"tags":{},"packages":[{"name":"libextractor","source":"https://ubuntu.com/security/cve?package=libextractor","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libextractor","debian":"https://tracker.debian.org/pkg/libextractor","statuses":[{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:1.3-4+deb9u3build0.16.04.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.3-4+deb9u1, 1:1.6-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:1.6-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-4641-1"],"notices":[{"id":"USN-4641-1","title":"libextractor vulnerabilities","summary":"Several security issues were fixed in libextractor.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-11-23T18:02:19.307565","description":"It was discovered that Libextractor incorrectly handled zero sample rate.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2017-15266)\n\nIt was discovered that Libextractor incorrectly handled certain FLAC\nmetadata. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2017-15267)\n\nIt was discovered that Libextractor incorrectly handled certain specially\ncrafted files. An attacker could possibly use this issue to cause a denial\nof service. (CVE-2017-15600, CVE-2018-16430, CVE-2018-20430)\n\nIt was discovered that Libextractor incorrectly handled certain inputs. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2017-15601)\n\nIt was discovered that Libextractor incorrectly handled integers. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2017-15602)\n\nIt was discovered that Libextractore incorrectly handled certain crafted\nfiles. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2017-15922)\n\nIt was discovered tha Libextractor incorrectly handled certain files. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2017-17440)\n\nIt was discovered that Libextractor incorrectly handled certain malformed\nfiles. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2018-14346)\n\nIt was discovered that Libextractor incorrectly handled malformed files. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2018-14347)\n\nIt was discovered that Libextractor incorrectly handled metadata. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2018-20431)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"libextractor","version":"1:1.3-4+deb9u3build0.16.04.1","description":"library used to extract metadata from files","is_source":true},{"name":"extract","version":"1:1.3-4+deb9u3build0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libextractor","version_link":"https://launchpad.net/ubuntu/+source/libextractor/1:1.3-4+deb9u3build0.16.04.1","pocket":"security"},{"name":"libextractor-dev","version":"1:1.3-4+deb9u3build0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libextractor","version_link":"https://launchpad.net/ubuntu/+source/libextractor/1:1.3-4+deb9u3build0.16.04.1","pocket":"security"},{"name":"libextractor3","version":"1:1.3-4+deb9u3build0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libextractor","version_link":"https://launchpad.net/ubuntu/+source/libextractor/1:1.3-4+deb9u3build0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-14346","CVE-2018-16430","CVE-2017-15266","CVE-2017-15601","CVE-2017-15602","CVE-2018-14347","CVE-2017-15922","CVE-2018-20431","CVE-2017-15600","CVE-2017-17440","CVE-2017-15267","CVE-2018-20430"]}]},{"id":"CVE-2015-6961","published":"2017-10-18T20:29:00","updated_at":"2025-08-25T21:44:28.305060+00:00","description":"\nOpen redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows\nremote attackers to redirect users to arbitrary web sites and conduct\nphishing attacks via a URL in the _next parameter to user/logout.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/web2py/web2py/issues/731","https://github.com/web2py/web2py/commit/e31a099cb3456fef471886339653430ae59056b0","https://www.cve.org/CVERecord?id=CVE-2015-6961"],"bugs":[""],"patches":{"web2py":[]},"tags":{},"packages":[{"name":"web2py","source":"https://ubuntu.com/security/cve?package=web2py","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=web2py","debian":"https://tracker.debian.org/pkg/web2py","statuses":[{"release_codename":"artful","status":"not-affected","description":"2.12.3-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.12.3-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.12.3-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.12.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5740","published":"2017-10-18T20:29:00","updated_at":"2025-09-15T19:15:13.227377+00:00","description":"\nThe net/http library in net/http/transfer.go in Go before 1.4.3 does not\nproperly parse HTTP headers, which allows remote attackers to conduct HTTP\nrequest smuggling attacks via a request with two Content-length headers.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"gccgo includes this part of the language library"},{"author":"mdeslaur","note":"Packages built using golang need to be rebuilt once the\nvulnerability has been fixed. This CVE entry does not\nlist packages that need rebuilding outside of the main\nrepository or the Ubuntu variants with PPA overlays."}],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/golang/go/commit/300d9a21583e7cf0149a778a0611e76ff7c6680f","https://www.cve.org/CVERecord?id=CVE-2015-5740"],"bugs":[""],"patches":{"golang":["upstream: https://github.com/golang/go/commit/300d9a21583e7cf0149a778a0611e76ff7c6680f"],"gccgo-5":[],"gccgo-4.9":[],"gccgo-4.8":[],"gccgo-4.7":[]},"tags":{},"packages":[{"name":"gccgo-4.7","source":"https://ubuntu.com/security/cve?package=gccgo-4.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gccgo-4.7","debian":"https://tracker.debian.org/pkg/gccgo-4.7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"gccgo-4.8","source":"https://ubuntu.com/security/cve?package=gccgo-4.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gccgo-4.8","debian":"https://tracker.debian.org/pkg/gccgo-4.8","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"gccgo-4.9","source":"https://ubuntu.com/security/cve?package=gccgo-4.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gccgo-4.9","debian":"https://tracker.debian.org/pkg/gccgo-4.9","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"gccgo-5","source":"https://ubuntu.com/security/cve?package=gccgo-5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gccgo-5","debian":"https://tracker.debian.org/pkg/gccgo-5","statuses":[{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"golang","source":"https://ubuntu.com/security/cve?package=golang","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang","debian":"https://tracker.debian.org/pkg/golang","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5beta1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2:1.5.1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-5739","published":"2017-10-18T20:29:00","updated_at":"2025-09-15T19:30:11.418227+00:00","description":"\nThe net/http library in net/textproto/reader.go in Go before 1.4.3 does not\nproperly parse HTTP header keys, which allows remote attackers to conduct\nHTTP request smuggling attacks via a space instead of a hyphen, as\ndemonstrated by \"Content Length\" instead of \"Content-Length.\"","ubuntu_description":"","notes":[{"author":"sbeattie","note":"looks to have been included since at least golang 1.0 release\ngccgo includes this part of the language library"},{"author":"mdeslaur","note":"Packages built using golang need to be rebuilt once the\nvulnerability has been fixed. This CVE entry does not\nlist packages that need rebuilding outside of the main\nrepository or the Ubuntu variants with PPA overlays."}],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/golang/go/commit/117ddcb83d7f42d6aa72241240af99ded81118e9","https://www.cve.org/CVERecord?id=CVE-2015-5739"],"bugs":[""],"patches":{"golang":["upstream: https://github.com/golang/go/commit/117ddcb83d7f42d6aa72241240af99ded81118e9"],"gccgo-5":[],"gccgo-4.9":[],"gccgo-4.8":[],"gccgo-4.7":[]},"tags":{},"packages":[{"name":"gccgo-4.7","source":"https://ubuntu.com/security/cve?package=gccgo-4.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gccgo-4.7","debian":"https://tracker.debian.org/pkg/gccgo-4.7","statuses":[{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"gccgo-4.8","source":"https://ubuntu.com/security/cve?package=gccgo-4.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gccgo-4.8","debian":"https://tracker.debian.org/pkg/gccgo-4.8","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"gccgo-4.9","source":"https://ubuntu.com/security/cve?package=gccgo-4.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gccgo-4.9","debian":"https://tracker.debian.org/pkg/gccgo-4.9","statuses":[{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"gccgo-5","source":"https://ubuntu.com/security/cve?package=gccgo-5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gccgo-5","debian":"https://tracker.debian.org/pkg/gccgo-5","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"golang","source":"https://ubuntu.com/security/cve?package=golang","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang","debian":"https://tracker.debian.org/pkg/golang","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.5beta1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"2:1.5.1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5714","published":"2017-10-18T18:29:00","updated_at":"2025-08-25T22:07:04.695722+00:00","description":"\nPuppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent\n1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist\nprotection mechanism and execute arbitrary code on Puppet nodes via vectors\nrelated to command validation, aka \"Puppet Execution Protocol (PXP) Command\nWhitelist Validation Vulnerability.\"","ubuntu_description":"","notes":[{"author":"ratliff","note":"Upstream says \"Default configurations of FOSS Puppet Agent are not vulnerable.\""}],"codename":null,"priority":"medium","cvss3":7.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugs.gentoo.org/597684","https://puppet.com/security/cve/pxp-agent-oct-2016","https://security.gentoo.org/glsa/201710-12","https://www.cve.org/CVERecord?id=CVE-2016-5714"],"bugs":[""],"patches":{"puppet":[]},"tags":{},"packages":[{"name":"puppet","source":"https://ubuntu.com/security/cve?package=puppet","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=puppet","debian":"https://tracker.debian.org/pkg/puppet","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-7943","published":"2017-10-18T18:29:00","updated_at":"2025-08-26T11:53:04.777261+00:00","description":"\nOpen redirect vulnerability in the Overlay module in Drupal 7.x before\n7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the\nLABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect\nusers to arbitrary web sites and conduct phishing attacks via unspecified\nvectors. NOTE: this vulnerability exists because of an incomplete fix for\nCVE-2015-3233.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.drupal.org/SA-CORE-2015-004","http://www.openwall.com/lists/oss-security/2015/10/21/6","https://www.cve.org/CVERecord?id=CVE-2015-7943"],"bugs":[""],"patches":{"drupal7":[]},"tags":{},"packages":[{"name":"drupal7","source":"https://ubuntu.com/security/cve?package=drupal7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal7","debian":"https://tracker.debian.org/pkg/drupal7","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.41-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"7.44-1ubuntu1~16.04.0","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-1239","published":"2017-10-18T17:29:00","updated_at":"2025-08-25T21:33:59.973173+00:00","description":"\nDouble free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG\nbefore r2997, as used in PDFium in Google Chrome, allows remote attackers\nto cause a denial of service (process crash) via a crafted PDF.","ubuntu_description":"","notes":[{"author":"eslerm","note":"j2k_read_ppm_v3 refactored with merge 28c6f54 which includes d1b053a and c887df1"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugs.chromium.org/p/chromium/issues/detail?id=430891","https://bugs.chromium.org/p/chromium/issues/detail?id=457493","https://gist.github.com/bittorrent3389/8fee7cdaa73d1d351ee9","https://github.com/uclouvain/openjpeg/commit/28c6f547987e8cbe5ccaef622da4cf6667068989","https://www.cve.org/CVERecord?id=CVE-2015-1239"],"bugs":[""],"patches":{"openjpeg2":["upstream: https://github.com/uclouvain/openjpeg/commit/d1b053afe2916ad65e53d2c7f4d66e5a8d1df3e7","upstream: https://github.com/uclouvain/openjpeg/commit/c887df12a38ff1a2721d0c8a93b74fe1d02701a2"],"openjpeg":[]},"tags":{},"packages":[{"name":"openjpeg","source":"https://ubuntu.com/security/cve?package=openjpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjpeg","debian":"https://tracker.debian.org/pkg/openjpeg","statuses":[{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"openjpeg2","source":"https://ubuntu.com/security/cve?package=openjpeg2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjpeg2","debian":"https://tracker.debian.org/pkg/openjpeg2","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.1.2-1.1+deb9u2build0.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.1.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.3.0-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.3.1-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.4.0-6","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.1.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-2156","published":"2017-10-18T15:29:00","updated_at":"2025-08-26T11:52:37.922388+00:00","description":"\nNetty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before\n4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before\n2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies\nand obtain sensitive information by leveraging improper validation of\ncookie name and value characters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://netty.io/news/2015/05/08/3-9-8-Final-and-3.html","https://www.playframework.com/security/vulnerability/CVE-2015-2156-HttpOnlyBypass","http://engineering.linkedin.com/security/look-netty%E2%80%99s-recent-security-update-cve%C2%AD-2015%C2%AD-2156","https://github.com/slandelle/netty/commit/800555417e77029dcf8a31d7de44f27b5a8f79b8","https://www.cve.org/CVERecord?id=CVE-2015-2156"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=796114","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=793770","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=646523"],"patches":{"netty3.1":[],"netty":[],"netty-3.9":["upstream: https://github.com/slandelle/netty/commit/52b80e50ded14b44ea3e4cbd30e5d7f864f88d85"]},"tags":{},"packages":[{"name":"netty-3.9","source":"https://ubuntu.com/security/cve?package=netty-3.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty-3.9","debian":"https://tracker.debian.org/pkg/netty-3.9","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.9.9.Final-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.9.9.Final-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.9.9.Final-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.9.9.Final-1, 1:4.0.31-1, 1:4.1.7-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:4.0.34-1","component":null,"pocket":"security"}]},{"name":"netty3.1","source":"https://ubuntu.com/security/cve?package=netty3.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty3.1","debian":"https://tracker.debian.org/pkg/netty3.1","statuses":[{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-5320","published":"2017-10-18T14:29:00","updated_at":"2025-08-25T20:23:27.028044+00:00","description":"\nscanf and related functions in glibc before 2.15 allow local users to cause\na denial of service (segmentation fault) via a large string of 0s.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"other long strings also crash scanf but only 0 is representable,\nthe standard is slightly lenient here. Second patch may not be strictly\nnecessary, see the discussion at the bug report for opinions."}],"codename":null,"priority":"low","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/03/12","https://www.cve.org/CVERecord?id=CVE-2011-5320"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=13138#c4"],"patches":{"eglibc":["upstream: https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=3f8cc204fdd0","upstream: https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=20b38e0"],"glibc":["upstream: https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=3f8cc204fdd0","upstream: https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=20b38e0"]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"2.15-0ubuntu10.11","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"2.19-0ubuntu6.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.15","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.15","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"2.19-10ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"2.19-15ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15596","published":"2017-10-18T08:29:00","updated_at":"2025-08-25T22:27:15.658249+00:00","description":"\nAn issue was discovered in Xen 4.4.x through 4.9.x allowing ARM guest OS\nusers to cause a denial of service (prevent physical CPU usage) because of\nlock mishandling upon detection of an add-to-physmap error.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-235.html","https://www.cve.org/CVERecord?id=CVE-2017-15596"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.6.4-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15595","published":"2017-10-18T08:29:00","updated_at":"2025-08-25T22:27:15.658249+00:00","description":"\nAn issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users\nto cause a denial of service (unbounded recursion, stack consumption, and\nhypervisor crash) or possibly gain privileges via crafted page-table\nstacking.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-240.html","https://www.cve.org/CVERecord?id=CVE-2017-15595"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.6.4-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":54960,"limit":20,"total_results":79316}