UBUNTU-CVE-2016-0483
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-0483
UBUNTU-CVE-2016-0483
Summary:
Details: Unspecified vulnerability in Oracle Java SE 6u105, 7u91, and 8u66; Java SE Embedded 8u65; and JRockit R28.3.8 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a heap-based buffer overflow in the readImage function, which allows remote attackers to execute arbitrary code via crafted image data.
References: https://ubuntu.com/security/CVE-2016-0483, http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html, https://ubuntu.com/security/notices/USN-2884-1, https://ubuntu.com/security/notices/USN-2885-1, https://www.cve.org/CVERecord?id=CVE-2016-0483
Affected packages
Package
Name: openjdk-6
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
