First published: Tue Oct 18 2016(Updated: )
Oracle Java SE 6u131, 7u121, and 8u111 fixes an unspecified vulnerability in the 2D component (<a href="https://access.redhat.com/security/cve/CVE-2016-5556">CVE-2016-5556</a>). Upstream has CVSS scored this issue as: 9.6/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H External Reference: <a href="http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html#AppendixJAVA">http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html#AppendixJAVA</a>
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.7.0-oracle-1:1.7.0.121-1jpp.1.el5_11 | 1.7.0-oracle-1:1.7.0.121-1jpp.1.el5_11 |
redhat/java | <1.6.0-sun-1:1.6.0.131-1jpp.1.el5_11 | 1.6.0-sun-1:1.6.0.131-1jpp.1.el5_11 |
redhat/java | <1.8.0-oracle-1:1.8.0.111-1jpp.4.el6_8 | 1.8.0-oracle-1:1.8.0.111-1jpp.4.el6_8 |
redhat/java | <1.7.0-oracle-1:1.7.0.121-1jpp.1.el6_8 | 1.7.0-oracle-1:1.7.0.121-1jpp.1.el6_8 |
redhat/java | <1.6.0-sun-1:1.6.0.131-1jpp.1.el6_8 | 1.6.0-sun-1:1.6.0.131-1jpp.1.el6_8 |
redhat/java | <1.8.0-oracle-1:1.8.0.111-1jpp.4.el7 | 1.8.0-oracle-1:1.8.0.111-1jpp.4.el7 |
redhat/java | <1.7.0-oracle-1:1.7.0.121-1jpp.1.el7 | 1.7.0-oracle-1:1.7.0.121-1jpp.1.el7 |
redhat/java | <1.6.0-sun-1:1.6.0.131-1jpp.1.el7 | 1.6.0-sun-1:1.6.0.131-1jpp.1.el7 |
redhat/java | <1.7.0-ibm-1:1.7.0.9.60-1jpp.1.el5_11 | 1.7.0-ibm-1:1.7.0.9.60-1jpp.1.el5_11 |
redhat/java | <1.6.0-ibm-1:1.6.0.16.35-1jpp.1.el5_11 | 1.6.0-ibm-1:1.6.0.16.35-1jpp.1.el5_11 |
redhat/java | <1.8.0-ibm-1:1.8.0.3.20-1jpp.1.el6_8 | 1.8.0-ibm-1:1.8.0.3.20-1jpp.1.el6_8 |
redhat/java | <1.7.1-ibm-1:1.7.1.3.60-1jpp.1.el6_8 | 1.7.1-ibm-1:1.7.1.3.60-1jpp.1.el6_8 |
redhat/java | <1.6.0-ibm-1:1.6.0.16.35-1jpp.1.el6_8 | 1.6.0-ibm-1:1.6.0.16.35-1jpp.1.el6_8 |
redhat/java | <1.8.0-ibm-1:1.8.0.3.20-1jpp.1.el7_2 | 1.8.0-ibm-1:1.8.0.3.20-1jpp.1.el7_2 |
redhat/java | <1.7.1-ibm-1:1.7.1.3.60-1jpp.1.el7_2 | 1.7.1-ibm-1:1.7.1.3.60-1jpp.1.el7_2 |
redhat/java | <1.7.1-ibm-1:1.7.1.4.1-1jpp.1.el6_8 | 1.7.1-ibm-1:1.7.1.4.1-1jpp.1.el6_8 |
Oracle JDK 6 | =1.6.0-update121 | |
Oracle JDK 6 | =1.7.0-update111 | |
Oracle JDK 6 | =1.8.0-update102 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update121 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update111 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update102 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2016-5556 has a CVSS score of 9.6, indicating a critical vulnerability.
To fix CVE-2016-5556, update your Java installation to the versions specified in the vendor's advisory.
CVE-2016-5556 affects Oracle Java SE 6u131, 7u121, and 8u111.
There are no known workarounds for CVE-2016-5556, so updating is the best approach.
CVE-2016-5556 impacts the 2D component of Oracle Java.