java-1.7.0-openjdk-1.7.0.141-2.6.10.0.0.1.el7.AXS7

エラータID: AXSA:2017-1653:02

リリース日: 
2017/05/17 Wednesday - 02:19
題名: 
java-1.7.0-openjdk-1.7.0.141-2.6.10.0.0.1.el7.AXS7
影響のあるチャネル: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

The OpenJDK runtime environment.

Security issues fixed with this release:

CVE-2017-3509
Vulnerability in the Java SE, Java SE Embedded component of Oracle
Java SE (subcomponent: Networking). Supported versions that are
affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121.
Difficult to exploit vulnerability allows unauthenticated attacker
with network access via multiple protocols to compromise Java SE, Java
SE Embedded. Successful attacks require human interaction from a
person other than the attacker. Successful attacks of this
vulnerability can result in unauthorized update, insert or delete
access to some of Java SE, Java SE Embedded accessible data as well as
unauthorized read access to a subset of Java SE, Java SE Embedded
accessible data. Note: This vulnerability applies to Java deployments,
typically in clients running sandboxed Java Web Start applications or
sandboxed Java applets, that load and run untrusted code (e.g., code
that comes from the internet) and rely on the Java sandbox for
security. This vulnerability does not apply to Java deployments,
typically in servers, that load and run only trusted code (e.g., code
installed by an administrator). CVSS 3.0 Base Score 4.2
(Confidentiality and Integrity impacts). CVSS Vector:
(CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).
CVE-2017-3511
Vulnerability in the Java SE, Java SE Embedded, JRockit component of
Oracle Java SE (subcomponent: JCE). Supported versions that are
affected are Java SE: 7u131 and 8u121; Java SE Embedded: 8u121;
JRockit: R28.3.13. Difficult to exploit vulnerability allows
unauthenticated attacker with logon to the infrastructure where Java
SE, Java SE Embedded, JRockit executes to compromise Java SE, Java SE
Embedded, JRockit. Successful attacks require human interaction from a
person other than the attacker and while the vulnerability is in Java
SE, Java SE Embedded, JRockit, attacks may significantly impact
additional products. Successful attacks of this vulnerability can
result in takeover of Java SE, Java SE Embedded, JRockit. Note:
Applies to client and server deployment of Java. This vulnerability
can be exploited through sandboxed Java Web Start applications and
sandboxed Java applets. It can also be exploited by supplying data to
APIs in the specified Component without using sandboxed Java Web Start
applications or sandboxed Java applets, such as through a web service.
CVSS 3.0 Base Score 7.7 (Confidentiality, Integrity and Availability
impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
CVE-2017-3526
Vulnerability in the Java SE, Java SE Embedded, JRockit component of
Oracle Java SE (subcomponent: JAXP). Supported versions that are
affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121;
JRockit: R28.3.13. Difficult to exploit vulnerability allows
unauthenticated attacker with network access via multiple protocols to
compromise Java SE, Java SE Embedded, JRockit. Successful attacks of
this vulnerability can result in unauthorized ability to cause a hang
or frequently repeatable crash (complete DOS) of Java SE, Java SE
Embedded, JRockit. Note: Applies to client and server deployment of
Java. This vulnerability can be exploited through sandboxed Java Web
Start applications and sandboxed Java applets. It can also be
exploited by supplying data to APIs in the specified Component without
using sandboxed Java Web Start applications or sandboxed Java applets,
such as through a web service. CVSS 3.0 Base Score 5.9 (Availability
impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).
CVE-2017-3533
Vulnerability in the Java SE, Java SE Embedded, JRockit component of
Oracle Java SE (subcomponent: Networking). Supported versions that are
affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121;
JRockit: R28.3.13. Difficult to exploit vulnerability allows
unauthenticated attacker with network access via FTP to compromise
Java SE, Java SE Embedded, JRockit. Successful attacks of this
vulnerability can result in unauthorized update, insert or delete
access to some of Java SE, Java SE Embedded, JRockit accessible data.
Note: Applies to client and server deployment of Java. This
vulnerability can be exploited through sandboxed Java Web Start
applications and sandboxed Java applets. It can also be exploited by
supplying data to APIs in the specified Component without using
sandboxed Java Web Start applications or sandboxed Java applets, such
as through a web service. CVSS 3.0 Base Score 3.7 (Integrity impacts).
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
CVE-2017-3539
Vulnerability in the Java SE, Java SE Embedded component of Oracle
Java SE (subcomponent: Security). Supported versions that are affected
are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121.
Difficult to exploit vulnerability allows unauthenticated attacker
with network access via multiple protocols to compromise Java SE, Java
SE Embedded. Successful attacks require human interaction from a
person other than the attacker. Successful attacks of this
vulnerability can result in unauthorized update, insert or delete
access to some of Java SE, Java SE Embedded accessible data. Note:
This vulnerability applies to Java deployments, typically in clients
running sandboxed Java Web Start applications or sandboxed Java
applets, that load and run untrusted code (e.g., code that comes from
the internet) and rely on the Java sandbox for security. This
vulnerability does not apply to Java deployments, typically in
servers, that load and run only trusted code (e.g., code installed by
an administrator). CVSS 3.0 Base Score 3.1 (Integrity impacts). CVSS
Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).
CVE-2017-3544
Vulnerability in the Java SE, Java SE Embedded, JRockit component of
Oracle Java SE (subcomponent: Networking). Supported versions that are
affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121;
JRockit: R28.3.13. Difficult to exploit vulnerability allows
unauthenticated attacker with network access via SMTP to compromise
Java SE, Java SE Embedded, JRockit. Successful attacks of this
vulnerability can result in unauthorized update, insert or delete
access to some of Java SE, Java SE Embedded, JRockit accessible data.
Note: Applies to client and server deployment of Java. This
vulnerability can be exploited through sandboxed Java Web Start
applications and sandboxed Java applets. It can also be exploited by
supplying data to APIs in the specified Component without using
sandboxed Java Web Start applications or sandboxed Java applets, such
as through a web service. CVSS 3.0 Base Score 3.7 (Integrity impacts).
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

解決策: 

Update package.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. java-1.7.0-openjdk-1.7.0.141-2.6.10.0.0.1.el7.AXS7.src.rpm
    MD5: 675f44ee66b160af175c0dfacca0251a
    SHA-256: c405dd02ef7486b7b7cb98b6b4034bafc53dac87160ce0f23bbbc7d4b29da5df
    Size: 39.08 MB

Asianux Server 7 for x86_64
  1. java-1.7.0-openjdk-1.7.0.141-2.6.10.0.0.1.el7.AXS7.x86_64.rpm
    MD5: 2c4ce8b5fe81fb41db09efecb3de0f8b
    SHA-256: 603802d97e1c33ab778356e5f0d513f1350c3dac08261cdf7d4c5c002fe01a0b
    Size: 230.01 kB
  2. java-1.7.0-openjdk-devel-1.7.0.141-2.6.10.0.0.1.el7.AXS7.x86_64.rpm
    MD5: 3a4787ca4d9cd0a32a76f90d964ed418
    SHA-256: 45bef43265ba8313f9210d5957dbe0ffaa82b58f077a16340f38b0c3d0a38a1b
    Size: 9.14 MB
  3. java-1.7.0-openjdk-headless-1.7.0.141-2.6.10.0.0.1.el7.AXS7.x86_64.rpm
    MD5: a46ef17c50ab7a445721bfbe4caab5da
    SHA-256: 11b85d99673aa2845121fbbc0f82e485fb5ad56ad35eb4826d614283f612c739
    Size: 25.42 MB