USN-3747-1
Dashboard / Vulnerabilities / USN-3747-1
USN-3747-1
Summary: openjdk-lts vulnerabilities
Details: It was discovered that OpenJDK did not properly validate types in some situations. An attacker could use this to construct a Java class that could possibly bypass sandbox restrictions. (CVE-2018-2825, CVE-2018-2826) It was discovered that the PatternSyntaxException class in OpenJDK did not properly validate arguments passed to it. An attacker could use this to potentially construct a class that caused a denial of service (excessive memory consumption). (CVE-2018-2952) Daniel Bleichenbacher discovered a vulnerability in the Galois/Counter Mode (GCM) mode of operation for symmetric block ciphers in OpenJDK. An attacker could use this to expose sensitive information. (CVE-2018-2972)
References: https://ubuntu.com/security/notices/USN-3747-1, https://ubuntu.com/security/CVE-2018-2825, https://ubuntu.com/security/CVE-2018-2826, https://ubuntu.com/security/CVE-2018-2952, https://ubuntu.com/security/CVE-2018-2972
Affected packages
Package
Name: openjdk-lts
Purl: pkg:deb/ubuntu/[email protected]+13-1ubuntu0.18.04.1?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
