Ubuntu Security Notice USN-3275-1
11th May, 2017
openjdk-8 vulnerabilities
A security issue affects these releases of Ubuntu and its
derivatives:
- Ubuntu 17.04
- Ubuntu 16.10
- Ubuntu 16.04 LTS
Summary
Several security issues were fixed in OpenJDK 8.
Software description
- openjdk-8
- Open Source Java implementation
Details
It was discovered that OpenJDK improperly re-used cached NTLM
connections in some situations. A remote attacker could possibly
use this to cause a Java application to perform actions with the
credentials of a different user. ()
It was discovered that the Java API for XML Processing (JAXP) component
in OpenJDK did not properly enforce size limits when parsing XML
documents. An attacker could use this to cause a denial of service
(processor and memory consumption). ()
It was discovered that OpenJDK allowed MD5 to be used as an algorithm
for JAR integrity verification. An attacker could possibly use this
to modify the contents of a JAR file without detection. ()
Update instructions
The problem can be corrected by updating your system to the following
package version:
- Ubuntu 17.04:
- Ubuntu 16.10:
- Ubuntu 16.04 LTS:
To update your system, please follow these instructions:
,
,
,
CVE-2017-3544
SOCIAL SHARE CARD GENERATOR