First published: Fri Jul 13 2018(Updated: )
It was discovered that the implementation of the PatternSyntaxException class in the Concurrency component of OpenJDK failed to sufficiently validate the 'index' value (to ensure it's not greater than the regular expression length) in the getMessage() method. An instance of the class with invalid index value, for example one created via deserialization on an untrusted input, could cause a Java application to use an excessive amount of memory.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JDK | =1.6.0-update191 | |
Oracle JDK | =1.7.0-update181 | |
Oracle JDK | =1.8.0-update172 | |
Oracle JDK | =10.0.1 | |
Oracle JRE | =1.6.0-update191 | |
Oracle JRE | =1.7.0-update181 | |
Oracle JRE | =1.8.0-update172 | |
Oracle JRE | =10.0.1 | |
Oracle JRockit | =r28.3.18 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Hp Xp7 Command View | ||
Redhat Satellite | =5.6 | |
Redhat Satellite | =5.7 | |
Redhat Satellite | =5.8 | |
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Eus | =7.5 | |
Redhat Enterprise Linux Eus | =7.6 | |
Redhat Enterprise Linux Eus | =7.7 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Server Aus | =7.6 | |
Redhat Enterprise Linux Server Aus | =7.7 | |
Redhat Enterprise Linux Server Tus | =7.6 | |
Redhat Enterprise Linux Server Tus | =7.7 | |
Redhat Enterprise Linux Workstation | =6.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Active Iq Unified Manager Windows | ||
Netapp Cloud Backup | ||
NetApp E-Series SANtricity OS Controller | >=11.0<=11.70.1 | |
Netapp E-series Santricity Storage Manager | ||
NetApp OnCommand Insight | ||
Netapp Oncommand Unified Manager | ||
NetApp OnCommand Workflow Automation | ||
Netapp Plug-in For Symantec Netbackup | ||
Netapp Snapmanager Oracle | ||
Netapp Snapmanager Sap | ||
Netapp Steelstore Cloud Integrated Storage | ||
Netapp Storage Replication Adapter For Clustered Data Ontap Vmware Vsphere | >=9.7 | |
Netapp Vasa Provider For Clustered Data Ontap | >=9.7 | |
Netapp Virtual Storage Console Vmware Vsphere | >=9.7 | |
debian/openjdk-8 | 8u432-b06-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2952 is a vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE, specifically in the Concurrency subcomponent.
Java SE versions 6u191, 7u181, 8u172, and 10.0.1 are affected by CVE-2018-2952.
CVE-2018-2952 has a difficulty level of 'Difficult to exploit' and does not require authentication.
CVE-2018-2952 has a severity value of 3.7, which is categorized as medium severity.
You can find more information about CVE-2018-2952 on the Oracle website and the Red Hat website.