Ubuntu Security Notice USN-3130-1

Discussion in 'News Aggregator' started by Packet Storm, 18 Nov 2016.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3130-1 - It was discovered that OpenJDK did not restrict the set of algorithms used for Jar integrity verification. An attacker could use this to modify without detection the content of a JAR file, affecting system integrity. It was discovered that the JMX component of OpenJDK did not sufficiently perform classloader consistency checks. An attacker could use this to bypass Java sandbox restrictions. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...