1
PublicDateAtUSN: 2017-10-19
2
Candidate: CVE-2017-10349
5
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10349
6
https://usn.ubuntu.com/usn/usn-3473-1
7
https://usn.ubuntu.com/usn/usn-3497-1
9
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE
10
(subcomponent: JAXP). Supported versions that are affected are Java SE:
11
6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable
12
vulnerability allows unauthenticated attacker with network access via
13
multiple protocols to compromise Java SE, Java SE Embedded. Successful
14
attacks of this vulnerability can result in unauthorized ability to cause a
15
partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note:
16
This vulnerability applies to Java deployments, typically in clients
17
running sandboxed Java Web Start applications or sandboxed Java applets,
18
that load and run untrusted code (e.g., code that comes from the internet)
19
and rely on the Java sandbox for security. This vulnerability does not
20
apply to Java deployments, typically in servers, that load and run only
21
trusted code (e.g., code installed by an administrator). CVSS 3.0 Base
22
Score 5.3 (Availability impacts). CVSS Vector:
23
(CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
25
It was discovered that the JAXP component in OpenJDK did not
26
properly limit the amount of memory allocated when performing
27
deserializations. An attacker could use this to cause a denial of
28
service (memory exhaustion).
36
upstream_openjdk-6: released
37
precise/esm_openjdk-6: DNE
38
trusty_openjdk-6: needed
46
upstream_openjdk-7: released
47
precise/esm_openjdk-7: DNE
48
trusty_openjdk-7: released (7u151-2.6.11-2ubuntu0.14.04.1)
56
upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jaxp/rev/202d9386f011
57
upstream_openjdk-8: released (8u151)
58
precise/esm_openjdk-8: DNE
60
xenial_openjdk-8: released (8u151-b12-0ubuntu0.16.04.2)
61
zesty_openjdk-8: released (8u151-b12-0ubuntu0.17.04.2)
62
artful_openjdk-8: released (8u151-b12-0ubuntu0.17.10.2)
63
bionic_openjdk-8: not-affected (8u151-b12-1)
64
devel_openjdk-8: not-affected (8u151-b12-1)
67
upstream_icedtea-web: not-affected
68
precise/esm_icedtea-web: DNE
69
trusty_icedtea-web: not-affected
70
xenial_icedtea-web: not-affected
71
zesty_icedtea-web: not-affected
72
artful_icedtea-web: not-affected
73
bionic_icedtea-web: not-affected
74
devel_icedtea-web: not-affected
77
upstream_openjdk-9: released (9.0.1)
78
precise/esm_openjdk-9: DNE
80
xenial_openjdk-9: needed
81
zesty_openjdk-9: ignored (reached end-of-life)
82
artful_openjdk-9: needed