CVE-2018-3214: Medium severity Oracle JDK vulnerability
An infinite loop flaw was found in the RIFF (Resource Interchange File Format) file format reader in the Sound component of OpenJDK. A specially crafted RIFF file could cause a Java application to enter an infinite loop while reading the RIFF file.
Other sources
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Sound). Supported versions that are affected are Java SE: 6u201, 7u191 and 8u182; Java SE Embedded: 8u181; JRockit: R28.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g. through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-3214.
What is the severity of CVE-2018-3214?
The severity of CVE-2018-3214 is medium.
Which versions of Java SE are affected by CVE-2018-3214?
Java SE versions 6u201, 7u191, and 8u182 are affected by CVE-2018-3214.
How can an attacker exploit CVE-2018-3214?
An unauthenticated attacker with network access can easily exploit CVE-2018-3214.
Where can I find more information about CVE-2018-3214?
You can find more information about CVE-2018-3214 at the following references: [https://bugs.openjdk.java.net/browse/JDK-8135160], [http://hg.openjdk.java.net/jdk9/jdk9/jdk/rev/420dd4208444], [https://www.modzero.ch/modlog/archives/2018/09/20/java_bugs_with_and_without_fuzzing/index.html].