CVE-2016-3443: Critical severity oracle java se 7 vulnerability
Oracle Java SE 6u115, 7u101 and 8u91 fixes an unspecified vulnerability in the 2D component (CVE-2016-3443). Upstream has CVSSv2 scored this issue as: 10.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2016-2881694.html#AppendixJAVA
Other sources
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D. NOTE: the previous information is from the April 2016 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information via crafted font data, which triggers an out-of-bounds read.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2016-3443?
CVE-2016-3443 has a CVSSv2 score of 10.0, indicating it is critical in severity.
How do I fix CVE-2016-3443?
To address CVE-2016-3443, update to the latest patched version of Java as specified by Oracle for your platform.
What versions of Java are affected by CVE-2016-3443?
CVE-2016-3443 affects Oracle Java SE versions 6u115, 7u101, and 8u91.
Is CVE-2016-3443 a remote vulnerability?
Yes, CVE-2016-3443 can be exploited remotely due to its nature, allowing potential attackers to exploit the vulnerability over a network.
What component is involved in CVE-2016-3443?
CVE-2016-3443 involves a vulnerability in the 2D component of Oracle Java.