public inbox for gentoo-announce@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-announce] [ GLSA 201710-31 ] Oracle JDK/JRE: Multiple vulnerabilities
@ 2017-10-29 22:47 Aaron Bauman
  0 siblings, 0 replies; only message in thread
From: Aaron Bauman @ 2017-10-29 22:47 UTC (permalink / raw
  To: gentoo-announce

[-- Attachment #1: Type: text/plain, Size: 4395 bytes --]

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 201710-31
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: Normal
    Title: Oracle JDK/JRE: Multiple vulnerabilities
     Date: October 29, 2017
     Bugs: #635030
       ID: 201710-31

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in Oracle's JDK and JRE
software suites, the worst of which can be remotely exploited without
authentication.

Background
==========

Java Platform, Standard Edition (Java SE) lets you develop and deploy
Java applications on desktops and servers, as well as in today’s
demanding embedded environments. Java offers the rich user interface,
performance, versatility, portability, and security that today’s
applications require.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  dev-java/oracle-jdk-bin   < 1.8.0.152-r1         >= 1.8.0.152-r1 
  2  dev-java/oracle-jre-bin   < 1.8.0.152-r1         >= 1.8.0.152-r1 
    -------------------------------------------------------------------
     2 affected packages

Description
===========

Multiple vulnerabilities have been discovered in Oracle’s Java  SE.
Please review the referenced CVE identifiers for details.

Impact
======

A remote attacker could cause a Denial of Service condition, modify
arbitrary data, or have numerous other impacts.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Oracle JDK users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot -v ">=dev-java/oracle-jdk-bin-1.8.0.152-r1"

All Oracle JRE users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot -v ">=dev-java/oracle-jre-bin-1.8.0.152-r1"

References
==========

[  1 ] CVE-2017-10274
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10274
[  2 ] CVE-2017-10281
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10281
[  3 ] CVE-2017-10285
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10285
[  4 ] CVE-2017-10293
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10293
[  5 ] CVE-2017-10295
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10295
[  6 ] CVE-2017-10309
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10309
[  7 ] CVE-2017-10345
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10345
[  8 ] CVE-2017-10346
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10346
[  9 ] CVE-2017-10347
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10347
[ 10 ] CVE-2017-10348
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10348
[ 11 ] CVE-2017-10349
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10349
[ 12 ] CVE-2017-10350
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10350
[ 13 ] CVE-2017-10355
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10355
[ 14 ] CVE-2017-10356
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10356
[ 15 ] CVE-2017-10357
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10357
[ 16 ] CVE-2017-10388
       https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10388

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/201710-31

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2017 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5

[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 488 bytes --]

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2017-10-29 22:49 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-10-29 22:47 [gentoo-announce] [ GLSA 201710-31 ] Oracle JDK/JRE: Multiple vulnerabilities Aaron Bauman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox