java-1.7.0-openjdk-1.7.0.141-2.6.10.1.AXS4

エラータID: AXSA:2017-1643:02

リリース日: 
2017/05/09 Tuesday - 18:01
題名: 
java-1.7.0-openjdk-1.7.0.141-2.6.10.1.AXS4
影響のあるチャネル: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
Moderate
Description: 

The OpenJDK runtime environment.

Security issues fixed with this release:

CVE-2017-3509
Vulnerability in the Java SE, Java SE Embedded component of Oracle
Java SE (subcomponent: Networking). Supported versions that are
affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121.
Difficult to exploit vulnerability allows unauthenticated attacker
with network access via multiple protocols to compromise Java SE, Java
SE Embedded. Successful attacks require human interaction from a
person other than the attacker. Successful attacks of this
vulnerability can result in unauthorized update, insert or delete
access to some of Java SE, Java SE Embedded accessible data as well as
unauthorized read access to a subset of Java SE, Java SE Embedded
accessible data. Note: This vulnerability applies to Java deployments,
typically in clients running sandboxed Java Web Start applications or
sandboxed Java applets, that load and run untrusted code (e.g., code
that comes from the internet) and rely on the Java sandbox for
security. This vulnerability does not apply to Java deployments,
typically in servers, that load and run only trusted code (e.g., code
installed by an administrator). CVSS 3.0 Base Score 4.2
(Confidentiality and Integrity impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).
CVE-2017-3511
Vulnerability in the Java SE, Java SE Embedded, JRockit component of
Oracle Java SE (subcomponent: JCE). Supported versions that are
affected are Java SE: 7u131 and 8u121; Java SE Embedded: 8u121;
JRockit: R28.3.13. Difficult to exploit vulnerability allows
unauthenticated attacker with logon to the infrastructure where Java
SE, Java SE Embedded, JRockit executes to compromise Java SE, Java SE
Embedded, JRockit. Successful attacks require human interaction from a
person other than the attacker and while the vulnerability is in Java
SE, Java SE Embedded, JRockit, attacks may significantly impact
additional products. Successful attacks of this vulnerability can
result in takeover of Java SE, Java SE Embedded, JRockit. Note:
Applies to client and server deployment of Java. This vulnerability
can be exploited through sandboxed Java Web Start applications and
sandboxed Java applets. It can also be exploited by supplying data to
APIs in the specified Component without using sandboxed Java Web Start
applications or sandboxed Java applets, such as through a web service.
CVSS 3.0 Base Score 7.7 (Confidentiality, Integrity and Availability
impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
CVE-2017-3526
Vulnerability in the Java SE, Java SE Embedded, JRockit component of
Oracle Java SE (subcomponent: JAXP). Supported versions that are
affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121;
JRockit: R28.3.13. Difficult to exploit vulnerability allows
unauthenticated attacker with network access via multiple protocols to
compromise Java SE, Java SE Embedded, JRockit. Successful attacks of
this vulnerability can result in unauthorized ability to cause a hang
or frequently repeatable crash (complete DOS) of Java SE, Java SE
Embedded, JRockit. Note: Applies to client and server deployment of
Java. This vulnerability can be exploited through sandboxed Java Web
Start applications and sandboxed Java applets. It can also be
exploited by supplying data to APIs in the specified Component without
using sandboxed Java Web Start applications or sandboxed Java applets,
such as through a web service. CVSS 3.0 Base Score 5.9 (Availability
impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-3533
Vulnerability in the Java SE, Java SE Embedded, JRockit component of
Oracle Java SE (subcomponent: Networking). Supported versions that are
affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121;
JRockit: R28.3.13. Difficult to exploit vulnerability allows
unauthenticated attacker with network access via FTP to compromise
Java SE, Java SE Embedded, JRockit. Successful attacks of this
vulnerability can result in unauthorized update, insert or delete
access to some of Java SE, Java SE Embedded, JRockit accessible data.
Note: Applies to client and server deployment of Java. This
vulnerability can be exploited through sandboxed Java Web Start
applications and sandboxed Java applets. It can also be exploited by
supplying data to APIs in the specified Component without using
sandboxed Java Web Start applications or sandboxed Java applets, such
as through a web service. CVSS 3.0 Base Score 3.7 (Integrity impacts).
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
CVE-2017-3539
Vulnerability in the Java SE, Java SE Embedded component of Oracle
Java SE (subcomponent: Security). Supported versions that are affected
are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121.
Difficult to exploit vulnerability allows unauthenticated attacker
with network access via multiple protocols to compromise Java SE, Java
SE Embedded. Successful attacks require human interaction from a
person other than the attacker. Successful attacks of this
vulnerability can result in unauthorized update, insert or delete
access to some of Java SE, Java SE Embedded accessible data. Note:
This vulnerability applies to Java deployments, typically in clients
running sandboxed Java Web Start applications or sandboxed Java
applets, that load and run untrusted code (e.g., code that comes from
the internet) and rely on the Java sandbox for security. This
vulnerability does not apply to Java deployments, typically in
servers, that load and run only trusted code (e.g., code installed by
an administrator). CVSS 3.0 Base Score 3.1 (Integrity impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).
CVE-2017-3544
Vulnerability in the Java SE, Java SE Embedded, JRockit component of
Oracle Java SE (subcomponent: Networking). Supported versions that are
affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121;
JRockit: R28.3.13. Difficult to exploit vulnerability allows
unauthenticated attacker with network access via SMTP to compromise
Java SE, Java SE Embedded, JRockit. Successful attacks of this
vulnerability can result in unauthorized update, insert or delete
access to some of Java SE, Java SE Embedded, JRockit accessible data.
Note: Applies to client and server deployment of Java. This
vulnerability can be exploited through sandboxed Java Web Start
applications and sandboxed Java applets. It can also be exploited by
supplying data to APIs in the specified Component without using
sandboxed Java Web Start applications or sandboxed Java applets, such
as through a web service. CVSS 3.0 Base Score 3.7 (Integrity impacts).
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

解決策: 

Update package.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. java-1.7.0-openjdk-1.7.0.141-2.6.10.1.AXS4.src.rpm
    MD5: b44f4d04b38ed8813ea9b7746e98dbf7
    SHA-256: 296578766391ee03928356f65e2902cbdb03629e7811ba3c5d663a261dfb0963
    Size: 39.19 MB

Asianux Server 4 for x86
  1. java-1.7.0-openjdk-1.7.0.141-2.6.10.1.AXS4.i686.rpm
    MD5: fcc5e977e4e23d3819aad996654ca432
    SHA-256: 88c3c2b7e6ebd1111c4c2744eaeb0cab57613727209ea20839af8f6c472b88f5
    Size: 27.55 MB
  2. java-1.7.0-openjdk-devel-1.7.0.141-2.6.10.1.AXS4.i686.rpm
    MD5: 1168dfc7de0df0e33b0ab50fea7e82d2
    SHA-256: c3d57774353dcb282859dbd4d66d4c39377b6c1e0e40f869140864cd1955f8bc
    Size: 9.47 MB

Asianux Server 4 for x86_64
  1. java-1.7.0-openjdk-1.7.0.141-2.6.10.1.AXS4.x86_64.rpm
    MD5: cf8cfb5f92dc100e7faba68a64783144
    SHA-256: 3d36349fa99cfe5b2f8fbc10c0dc016b49f988d6ad6443edcc6580a0108b310c
    Size: 26.35 MB
  2. java-1.7.0-openjdk-devel-1.7.0.141-2.6.10.1.AXS4.x86_64.rpm
    MD5: 1120d88dd541c0ae39e4dde175dce88f
    SHA-256: 479127ae34ef793c31596ff8b885752f7c480075dd4adf7fa80ce63901eb3716
    Size: 9.47 MB