{"id":"USN-3644-1","summary":"openjdk-8 vulnerabilities","details":"It was discovered that the Security component of OpenJDK did not\ncorrectly perform merging of multiple sections for the same file listed\nin JAR archive file manifests. An attacker could possibly use this to\nmodify attributes in a manifest without invalidating the signature.\n(CVE-2018-2790)\n\nFrancesco Palmarini, Marco Squarcina, Mauro Tempesta, and Riccardo Focardi\ndiscovered that the Security component of OpenJDK did not restrict which\nclasses could be used when deserializing keys from the JCEKS key stores. An\nattacker could use this to specially craft a JCEKS key store to execute\narbitrary code. (CVE-2018-2794)\n\nIt was discovered that the Security component of OpenJDK in some situations\ndid not properly limit the amount of memory allocated when performing\ndeserialization. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2018-2795)\n\nIt was discovered that the Concurrency component of OpenJDK in some\nsituations did not properly limit the amount of memory allocated when\nperforming deserialization. An attacker could use this to cause a\ndenial of service (memory exhaustion). (CVE-2018-2796)\n\nIt was discovered that the JMX component of OpenJDK in some situations did\nnot properly limit the amount of memory allocated when performing\ndeserialization. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2018-2797)\n\nIt was discovered that the AWT component of OpenJDK in some situations did\nnot properly limit the amount of memory allocated when performing\ndeserialization. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2018-2798)\n\nIt was discovered that the JAXP component of OpenJDK in some situations did\nnot properly limit the amount of memory allocated when performing\ndeserialization. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2018-2799)\n\nMoritz Bechler discovered that the RMI component of OpenJDK enabled HTTP\ntransport for RMI servers by default. A remote attacker could use this to\ngain access to restricted services. (CVE-2018-2800)\n\nIt was discovered that a vulnerability existed in the Hotspot component of\nOpenJDK affecting confidentiality, data integrity, and availability. An\nattacker could use this to specially craft an Java application that caused\na denial of service or bypassed sandbox restrictions. (CVE-2018-2814)\n\nApostolos Giannakidis discovered that the Serialization component\nof OpenJDK did not properly bound memory allocations in some\nsituations. An attacker could use this to cause a denial of service\n(memory exhaustion). (CVE-2018-2815)\n\nDavid Benjamin discovered a vulnerability in the Security component\nof OpenJDK related to data integrity and confidentiality. A remote\nattacker could possibly use this to expose sensitive information.\n(CVE-2018-2783)\n","modified":"2026-02-10T04:41:20Z","published":"2018-05-11T01:44:34Z","related":["UBUNTU-CVE-2018-2783","UBUNTU-CVE-2018-2790","UBUNTU-CVE-2018-2794","UBUNTU-CVE-2018-2795","UBUNTU-CVE-2018-2796","UBUNTU-CVE-2018-2797","UBUNTU-CVE-2018-2798","UBUNTU-CVE-2018-2799","UBUNTU-CVE-2018-2800","UBUNTU-CVE-2018-2814","UBUNTU-CVE-2018-2815"],"upstream":["CVE-2018-2783","CVE-2018-2790","CVE-2018-2794","CVE-2018-2795","CVE-2018-2796","CVE-2018-2797","CVE-2018-2798","CVE-2018-2799","CVE-2018-2800","CVE-2018-2814","CVE-2018-2815","UBUNTU-CVE-2018-2783","UBUNTU-CVE-2018-2790","UBUNTU-CVE-2018-2794","UBUNTU-CVE-2018-2795","UBUNTU-CVE-2018-2796","UBUNTU-CVE-2018-2797","UBUNTU-CVE-2018-2798","UBUNTU-CVE-2018-2799","UBUNTU-CVE-2018-2800","UBUNTU-CVE-2018-2814","UBUNTU-CVE-2018-2815"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-3644-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-2783"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-2790"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-2794"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-2795"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-2796"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-2797"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-2798"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-2799"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-2800"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-2814"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-2815"}],"affected":[{"package":{"name":"openjdk-8","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/openjdk-8@8u171-b11-0ubuntu0.16.04.1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8u171-b11-0ubuntu0.16.04.1"}]}],"versions":["8u66-b01-5","8u72-b05-1ubuntu1","8u72-b05-5","8u72-b05-6","8u72-b15-1","8u72-b15-2ubuntu1","8u72-b15-2ubuntu3","8u72-b15-3ubuntu1","8u77-b03-1ubuntu2","8u77-b03-3ubuntu1","8u77-b03-3ubuntu2","8u77-b03-3ubuntu3","8u91-b14-0ubuntu4~16.04.1","8u91-b14-3ubuntu1~16.04.1","8u111-b14-2ubuntu0.16.04.2","8u121-b13-0ubuntu1.16.04.2","8u131-b11-0ubuntu1.16.04.2","8u131-b11-2ubuntu1.16.04.2","8u131-b11-2ubuntu1.16.04.3","8u151-b12-0ubuntu0.16.04.2","8u162-b12-0ubuntu0.16.04.2"],"ecosystem_specific":{"binaries":[{"binary_name":"openjdk-8-demo","binary_version":"8u171-b11-0ubuntu0.16.04.1"},{"binary_name":"openjdk-8-jdk","binary_version":"8u171-b11-0ubuntu0.16.04.1"},{"binary_name":"openjdk-8-jdk-headless","binary_version":"8u171-b11-0ubuntu0.16.04.1"},{"binary_name":"openjdk-8-jre","binary_version":"8u171-b11-0ubuntu0.16.04.1"},{"binary_name":"openjdk-8-jre-headless","binary_version":"8u171-b11-0ubuntu0.16.04.1"},{"binary_name":"openjdk-8-jre-jamvm","binary_version":"8u171-b11-0ubuntu0.16.04.1"},{"binary_name":"openjdk-8-jre-zero","binary_version":"8u171-b11-0ubuntu0.16.04.1"},{"binary_name":"openjdk-8-source","binary_version":"8u171-b11-0ubuntu0.16.04.1"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:16.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","type":"CVSS_V3"},{"score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2018-2783"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","type":"CVSS_V3"},{"score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2018-2790"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2018-2794"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2018-2795"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2018-2796"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2018-2797"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2018-2798"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2018-2799"},{"severity":[{"score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2018-2800"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2018-2814"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2018-2815"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-3644-1.json"}}],"schema_version":"1.7.3"}