First published: Tue Apr 17 2018(Updated: )
It was discovered that the Security component of OpenJDK did not correctly perform merging of multiple sections for the same file listed in the JAR archive file manifest. An attacker could possibly use this flaw to alter certain attributes specified in the manifest without changing archive signature.
Credit: secalert_us@oracle.com secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openjdk-8 | 8u432-b06-2 | |
Oracle Java SE 7 | =1.6.0-update181 | |
Oracle Java SE 7 | =1.7.0-update171 | |
Oracle Java SE 7 | =1.8.0-update162 | |
Oracle Java SE 7 | =10 | |
Oracle JRE | =1.6.0-update181 | |
Oracle JRE | =1.7.0-update171 | |
Oracle JRE | =1.8.0-update162 | |
Oracle JRE | =10 | |
Red Hat Satellite | =5.6 | |
Red Hat Satellite | =5.7 | |
Red Hat Satellite | =5.8 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.5 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 | |
Debian Linux | =8.0 | |
Debian Linux | =9.0 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =17.10 | |
HP P9000 Command View Advanced Edition Software | ||
Schneider Electric EcoStruxure Data Center Expert | <7.6.0 | |
Oracle Java SE 7 | =1.10.0 | |
Oracle JRE | =1.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2790 is a vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE that allows an unauthenticated attacker with network access to exploit the system.
Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161.
CVE-2018-2790 has a severity rating of 3.1 (low).
Update to the recommended version: 8u382 or later for openjdk-8 (Debian) and apply the appropriate patches for Oracle JDK and JRE.
You can find more information about CVE-2018-2790 at the following links: [Oracle Security Advisory](http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html), [SecurityFocus](http://www.securityfocus.com/bid/103877), [SecurityTracker](http://www.securitytracker.com/id/1040697)