First published: Tue Apr 18 2017(Updated: )
It was discovered that the SMTP client implementation in the Networking component of OpenJDK failed to correctly handle sender and recipient addresses containing newline characters. A remote attacker could possibly use this flaw to manipulate an SMTP connection opened by a Java application if it could make it send an email to or from a specially crafted address.
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJDK 17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-1443068 has been identified as a potentially critical vulnerability allowing remote manipulation of SMTP connections.
To fix REDHAT-BUG-1443068, update to the latest version of OpenJDK that addresses this vulnerability.
REDHAT-BUG-1443068 affects the Networking component of OpenJDK, specifically versions of Oracle OpenJDK.
An attacker could exploit REDHAT-BUG-1443068 to manipulate SMTP connections opened by Java applications.
Yes, REDHAT-BUG-1443068 is specifically related to Java applications utilizing the OpenJDK Networking component.