First published: Tue Jan 17 2017(Updated: )
It was discovered that the URLStreamHandler class in the Networking component of OpenJDK failed to properly parse user info from the URL. A remote attacker could cause Java application to incorrectly parse attacker provided URL and interpret it differently from other applications processing the same URL.
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJDK |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1413882 is considered high due to the potential for remote exploitation.
To fix REDHAT-BUG-1413882, update your OpenJDK installation to the latest patched version.
A remote attacker could exploit REDHAT-BUG-1413882 to cause a Java application to incorrectly parse URLs.
REDHAT-BUG-1413882 affects multiple versions of OpenJDK, specifically any version prior to the security patch.
Yes, REDHAT-BUG-1413882 is related to the URLStreamHandler class in the Networking component of OpenJDK.