REDHAT-BUG-1471521: Openjdk vulnerability
Published Jul 16, 2017
·Updated
It was discovered that the implementation of the ThreadPoolExecutor class in the java.util.concurrent package of the Libraries component of OpenJDK failed to properly perform access control checks. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
Affected Software
1 affected component
OpenJDK OpenJDK
Event History
Jul 16, 2017
Data Sourced
via Red Hat·04:02 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Which advisories provide remediation and affected-package guidance?
The references include Oracle's July 2017 Critical Patch Update appendix for Java and Red Hat errata RHSA-2017:1792.
2
Is a source-level fix reference available for this issue?
Yes. The referenced OpenJDK change is revision e95a13de2d36 in the jdk8u source tree.