First published: Fri Jul 13 2018(Updated: )
It was discovered that the implementation of the PatternSyntaxException class in the Concurrency component of OpenJDK failed to sufficiently validate the 'index' value (to ensure it's not greater than the regular expression length) in the getMessage() method. An instance of the class with invalid index value, for example one created via deserialization on an untrusted input, could cause a Java application to use an excessive amount of memory.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openjdk-8 | 8u442-ga-2 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=17.0.0<=17.1.0 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=16.1.0<=16.1.3 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=15.1.0<=15.1.8 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=14.1.0<=14.1.5 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=13.1.0<=13.1.5 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=8.0.0<=8.4.0 | |
Oracle Java SE 7 | =1.6.0-update191 | |
Oracle Java SE 7 | =1.7.0-update181 | |
Oracle Java SE 7 | =1.8.0-update172 | |
Oracle Java SE 7 | =10.0.1 | |
Oracle JRE | =1.6.0-update191 | |
Oracle JRE | =1.7.0-update181 | |
Oracle JRE | =1.8.0-update172 | |
Oracle JRE | =10.0.1 | |
Oracle Java SE | =r28.3.18 | |
Debian Linux | =8.0 | |
Debian Linux | =9.0 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
HP P9000 Command View Advanced Edition Software | ||
Red Hat Satellite | =5.6 | |
Red Hat Satellite | =5.7 | |
Red Hat Satellite | =5.8 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server EUS | =7.5 | |
Red Hat Enterprise Linux Server EUS | =7.6 | |
Red Hat Enterprise Linux Server EUS | =7.7 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.7 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.7 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
NetApp Active IQ Unified Manager | ||
NetApp Cloud Backup | ||
NetApp E-Series SANtricity OS Controller | >=11.0<=11.70.1 | |
NetApp SANtricity Storage Manager | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Unified Manager for Windows | ||
NetApp OnCommand Workflow Automation | ||
NetApp Plug-in for Symantec NetBackup | ||
NetApp SnapManager for Oracle | ||
NetApp SnapManager for SAP | ||
NetApp SteelStore Cloud Integrated Storage | ||
NetApp Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere | >=9.7 | |
NetApp VASA Provider | >=9.7 | |
NetApp Virtual Storage Console for VMware vSphere | >=9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2952 is a vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE, specifically in the Concurrency subcomponent.
Java SE versions 6u191, 7u181, 8u172, and 10.0.1 are affected by CVE-2018-2952.
CVE-2018-2952 has a difficulty level of 'Difficult to exploit' and does not require authentication.
CVE-2018-2952 has a severity value of 3.7, which is categorized as medium severity.
You can find more information about CVE-2018-2952 on the Oracle website and the Red Hat website.