First published: Mon Jan 15 2018(Updated: )
It was discovered that the Hotspot component of OpenJDK failed to properly validate uses of the invokeinterface Java Virtual Machine instruction. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions.
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Build of OpenJDK with Hotspot |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1534768 is classified as critical due to the potential bypass of Java sandbox restrictions.
To fix REDHAT-BUG-1534768, update your OpenJDK Hotspot installation to the latest patched version.
REDHAT-BUG-1534768 affects systems running OpenJDK Hotspot where untrusted Java applications are executed.
Yes, REDHAT-BUG-1534768 can potentially allow an untrusted Java application to execute malicious code under the user's permissions.
Yes, REDHAT-BUG-1534768 involves a security flaw in the Java Virtual Machine that impacts its ability to enforce sandbox restrictions.