REDHAT-BUG-1730078: Low severity ORACLE OpenJDK vulnerability
It was discovered that the ChaCha20Cipher implementation in the Security component of OpenJDK used non-constant time comparison for comparing tags. A remote attacker could possible use the flaw to leak information about decryption state using the timing information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1730078?
The severity of REDHAT-BUG-1730078 is considered high due to the potential for information leakage based on timing attacks.
How do I fix REDHAT-BUG-1730078?
To fix REDHAT-BUG-1730078, you should update to the latest version of OpenJDK that includes the security patch.
Which software is affected by REDHAT-BUG-1730078?
REDHAT-BUG-1730078 affects Oracle OpenJDK 17 and potentially other versions if the flaw is present.
What type of vulnerability is REDHAT-BUG-1730078?
REDHAT-BUG-1730078 is a timing attack vulnerability involving non-constant time comparison in the ChaCha20Cipher implementation.
What can an attacker do with REDHAT-BUG-1730078?
An attacker exploiting REDHAT-BUG-1730078 could potentially leak sensitive information regarding the decryption state through timing analysis.