~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2018-2811

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2018-2811
2
 
PublicDate: 2018-04-18
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-2811
5
 
 http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
6
 
 http://www.securitytracker.com/id/1040697
7
 
Description:
8
 
 Vulnerability in the Java SE component of Oracle Java SE (subcomponent:
9
 
 Install). Supported versions that are affected are Java SE: 8u162 and 10.
10
 
 Difficult to exploit vulnerability allows unauthenticated attacker with
11
 
 logon to the infrastructure where Java SE executes to compromise Java SE.
12
 
 Successful attacks require human interaction from a person other than the
13
 
 attacker and while the vulnerability is in Java SE, attacks may
14
 
 significantly impact additional products. Successful attacks of this
15
 
 vulnerability can result in takeover of Java SE. Note: Applies to
16
 
 installation process on client deployment of Java. CVSS 3.0 Base Score 7.7
17
 
 (Confidentiality, Integrity and Availability impacts). CVSS Vector:
18
 
 (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
19
 
Ubuntu-Description:
20
 
Notes:
21
 
Bugs:
22
 
Priority: low
23
 
Discovered-by:
24
 
Assigned-to:
25
 
 
26
 
Patches_openjdk-8:
27
 
upstream_openjdk-8: needs-triage
28
 
precise/esm_openjdk-8: DNE
29
 
trusty_openjdk-8: DNE
30
 
xenial_openjdk-8: not-affected
31
 
artful_openjdk-8: not-affected
32
 
devel_openjdk-8: not-affected