{"id":"MGASA-2018-0104","summary":"Updated java-1.8.0-openjdk packages fix security vulnerability","details":"Multiple flaws were found in the Hotspot and AWT components of OpenJDK. An\nuntrusted Java application or applet could use these flaws to bypass certain\nJava sandbox restrictions (CVE-2018-2582, CVE-2018-2641).\n\nIt was discovered that the LDAPCertStore class in the JNDI component of\nOpenJDK failed to securely handle LDAP referrals. An attacker could possibly\nuse this flaw to make it fetch attacker controlled certificate data\n(CVE-2018-2633).\n\nThe JGSS component of OpenJDK ignores the value of the\njavax.security.auth.useSubjectCredsOnly property when using HTTP/SPNEGO\nauthentication and always uses global credentials. It was discovered that this\ncould cause global credentials to be unexpectedly used by an untrusted Java\napplication (CVE-2018-2634).\n\nIt was discovered that the JMX component of OpenJDK failed to properly set the\ndeserialization filter for the SingleEntryRegistry in certain cases. A remote\nattacker could possibly use this flaw to bypass intended deserialization\nrestrictions (CVE-2018-2637).\n\nIt was discovered that the LDAP component of OpenJDK failed to properly encode\nspecial characters in user names when adding them to an LDAP search query. A\nremote attacker could possibly use this flaw to manipulate LDAP queries\nperformed by the LdapLoginModule class (CVE-2018-2588).\n\nIt was discovered that the DNS client implementation in the JNDI component of\nOpenJDK did not use random source ports when sending out DNS queries. This\ncould make it easier for a remote attacker to spoof responses to those queries\n(CVE-2018-2599).\n\nIt was discovered that the I18n component of OpenJDK could use an untrusted\nsearch path when loading resource bundle classes. A local attacker could\npossibly use this flaw to execute arbitrary code as another local user by\nmaking their Java application load an attacker controlled class file\n(CVE-2018-2602).\n\nIt was discovered that the Libraries component of OpenJDK failed to\nsufficiently limit the amount of memory allocated when reading DER encoded\ninput. A remote attacker could possibly use this flaw to make a Java\napplication use an excessive amount of memory if it parsed attacker supplied\nDER encoded input (CVE-2018-2603).\n\nIt was discovered that the key agreement implementations in the JCE component\nof OpenJDK did not guarantee sufficient strength of used keys to adequately\nprotect generated shared secret. This could make it easier to break data\nencryption by attacking key agreement rather than the encryption using the\nnegotiated secret (CVE-2018-2618).\n\nIt was discovered that the JGSS component of OpenJDK failed to properly handle\nGSS context in the native GSS library wrapper in certain cases. A remote\nattacker could possibly make a Java application using JGSS to use a previously\nfreed context (CVE-2018-2629).\n\nIt was discovered that multiple classes in the Libraries, AWT, and JNDI\ncomponents of OpenJDK did not sufficiently validate input when creating object\ninstances from the serialized form. A specially-crafted input could cause a\nJava application to create objects with an inconsistent state or use an\nexcessive amount of memory when deserialized (CVE-2018-2663, CVE-2018-2677,\nCVE-2018-2678).\n\nIt was discovered that multiple encryption key classes in the Libraries\ncomponent of OpenJDK did not properly synchronize access to their internal\ndata. This could possibly cause a multi-threaded Java application to apply\nweak encryption to data because of the use of a key that was zeroed out\n(CVE-2018-2579).\n","modified":"2026-04-16T06:23:05.820375930Z","published":"2018-02-02T12:33:47Z","upstream":["CVE-2018-2579","CVE-2018-2582","CVE-2018-2588","CVE-2018-2599","CVE-2018-2602","CVE-2018-2603","CVE-2018-2618","CVE-2018-2629","CVE-2018-2633","CVE-2018-2634","CVE-2018-2637","CVE-2018-2641","CVE-2018-2663","CVE-2018-2677","CVE-2018-2678"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2018-0104.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=22411"},{"type":"ADVISORY","url":"http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:0095"}],"affected":[{"package":{"name":"java-1.8.0-openjdk","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/java-1.8.0-openjdk?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0.161-1.b14.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2018-0104.json"}},{"package":{"name":"java-1.8.0-openjdk","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/java-1.8.0-openjdk?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0.161-1.b14.1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2018-0104.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}