First published: Tue Oct 16 2018(Updated: )
It was discovered that the Security component of OpenJDK could incorrectly use unsigned manifest attribute entries when only properly signed entries were meant to be used. This could lead to bypass of protections provided by Jar signing. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.25+9-1~deb11u1 11.0.26+4-1 | |
debian/openjdk-8 | 8u432-b06-2 | |
Oracle Java SE 7 | =1.6.0-update201 | |
Oracle Java SE 7 | =1.7.0-update191 | |
Oracle Java SE 7 | =1.8.0-update181 | |
Oracle Java SE 7 | =1.8.0-update182 | |
Oracle Java SE 7 | =11.0.0 | |
Oracle JRE | =1.6.0-update201 | |
Oracle JRE | =1.7.0-update191 | |
Oracle JRE | =1.8.0-update181 | |
Oracle JRE | =1.8.0-update182 | |
Oracle JRE | =11.0.0 | |
Red Hat Satellite | =5.6 | |
Red Hat Satellite | =5.7 | |
Red Hat Satellite | =5.8 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server EUS | =7.6 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.5 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Workstation | =6.0 | |
Red Hat Enterprise Linux Workstation | =7.0 | |
Debian Linux | =8.0 | |
Debian Linux | =9.0 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =18.04 | |
Ubuntu | =18.10 | |
HP P9000 Command View Advanced Edition Software | <8.6.3-00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3136 is a vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security).
CVE-2018-3136 affects Java SE versions 6u201, 7u191, 8u182, and 11.
Yes, CVE-2018-3136 is a difficult to exploit vulnerability.
Systems running Oracle Java JDK/JRE versions 1.6.0-update201, 1.7.0-update191, 1.8.0-update181, 1.8.0-update182, and 11.0.0 are affected by CVE-2018-3136.
You can find more information about CVE-2018-3136 at the following references: [Oracle's Security Advisory](https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html#AppendixJAVA), [RedHat's Errata RHSA-2018:2942](https://access.redhat.com/errata/RHSA-2018:2942), [RedHat's Errata RHSA-2018:2943](https://access.redhat.com/errata/RHSA-2018:2943).