First published: Tue Jul 16 2019(Updated: )
It was discovered that the implementation of the Throwable class in the Utilities component of OpenJDK did not sufficiently validate serial stream before deserializing suppressed exceptions. A specially-crafted input could cause a Java application to construct inconsistent object and possibly use an excessive amount of system resources when deserialized.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JDK | =1.7.0-update221 | |
Oracle JDK | =1.8.0-update211 | |
Oracle JDK | =1.8.0-update212 | |
Oracle JDK | =11.0.3 | |
Oracle JDK | =12.0.1 | |
Oracle JRE | =1.7.0-update221 | |
Oracle JRE | =1.8.0-update211 | |
Oracle JRE | =1.8.0-update212 | |
Oracle JRE | =11.0.3 | |
Oracle JRE | =12.0.1 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.04 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 | |
Debian Debian Linux | =8.0 | |
Redhat Satellite | =5.8 | |
Redhat Enterprise Linux | =8.0 | |
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Eus | =8.6 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Workstation | =6.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
McAfee ePolicy Orchestrator | =5.9.0 | |
McAfee ePolicy Orchestrator | =5.9.1 | |
McAfee ePolicy Orchestrator | =5.10.0 | |
McAfee ePolicy Orchestrator | =5.10.0-update_1 | |
McAfee ePolicy Orchestrator | =5.10.0-update_2 | |
McAfee ePolicy Orchestrator | =5.10.0-update_3 | |
McAfee ePolicy Orchestrator | =5.10.0-update_4 | |
Hp Xp7 Command View | <8.7.0-00 | |
debian/openjdk-11 | 11.0.24+8-2~deb11u1 11.0.25+9-1~deb11u1 11.0.26~6ea-1 | |
debian/openjdk-8 | 8u432-b06-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-2762 is medium with a CVSS score of 5.3.
To fix the vulnerability CVE-2019-2762, you should update to the following versions: Java SE: 12.0.2+9-1 or later, Java SE Embedded: 8u211 or later.
The affected versions of Oracle Java SE are Java SE: 7u221, 8u212, 11.0.3, and 12.0.1.
Yes, you can refer to the following advisories: [Oracle Security Advisory](http://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html), [Ubuntu Security Notice 4080-1](https://usn.ubuntu.com/4080-1/), [Ubuntu Security Notice 4083-1](https://usn.ubuntu.com/4083-1/).
The affected software packages are openjdk-12 and openjdk-8 on Ubuntu, Oracle JDK and Oracle JRE, Canonical Ubuntu Linux, openSUSE Leap, Debian Debian Linux, Redhat Satellite, Redhat Enterprise Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Eus, Redhat Enterprise Linux Server, Redhat Enterprise Linux Workstation, McAfee ePolicy Orchestrator, and Hp Xp7 Command View.