First published: Wed Oct 17 2018(Updated: )
A flaw was found in the Utility component of OpenJDK. The Multi-Release attribute could have been read from outside of the main attributes in a Jar manifest, possibly leading to a use of an unsigned value for this attribute. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JDK | =11.0.0 | |
Oracle JRE | =11.0.0 | |
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.25+9-1~deb11u1 11.0.26~6ea-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3150 is a vulnerability in the Java SE component of Oracle Java SE that allows an unauthenticated attacker with network access to compromise Java SE.
The severity of CVE-2018-3150 is medium with a severity value of 3.7 on a scale of 10.
The affected software includes Java SE 11, OpenJDK 11, Oracle JDK, and Oracle JRE.
To fix CVE-2018-3150, update to the recommended versions of the affected software.
For more information about CVE-2018-3150, you can refer to the Oracle Security Advisory, JDK Updates, and Red Hat Errata links provided.