First published: Fri Oct 13 2017(Updated: )
It was discovered that the CardImpl class in the Smart Card IO component of OpenJDK failed to properly update its state in the finalize() method. An untrusted Java application or applet could possibly use this flaw to gain unexpected access to a smart card, bypassing certain Java sandbox restrictions.
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJDK 17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability REDHAT-BUG-1502053 is rated as high severity due to its potential to allow unauthorized access to smart cards.
To fix REDHAT-BUG-1502053, you should update to the latest version of the OpenJDK that addresses this vulnerability.
The REDHAT-BUG-1502053 vulnerability affects users running the OpenJDK 17 on systems using the Smart Card IO component.
Yes, an untrusted Java application can exploit REDHAT-BUG-1502053 to gain unexpected access to smart cards.
Yes, REDHAT-BUG-1502053 has the potential to bypass certain Java sandbox restrictions.