
USN-3275-1: OpenJDK 8 vulnerabilities
USN-3275-1: OpenJDK 8 vulnerabilities Ubuntu Security Notice USN-3275-1 11th May, 2017 openjdk-8 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Summary Several security issues were fixed in OpenJDK 8. Software description openjdk-8 – Open Source Java implementation Details It was discovered that OpenJDK improperly re-used cached NTLMconnections in some situations. A remote attacker could possiblyuse this to cause a Java application to perform actions with thecredentials of a different user. (CVE-2017-3509) It was discovered that an untrusted library search path flaw existedin the Java Cryptography Extension (JCE) component of OpenJDK. Alocal attacker could possibly use this to gain the privileges of aJava application. (CVE-2017-3511) It was discovered that the Java API for XML Processing (JAXP) componentin OpenJDK did not properly enforce size limits when parsing XMLdocuments. An attacker could [ more… ]