Debian Security Advisory DSA 3381-1 (openjdk-7 - security update)

Published: 2015-10-26 23:00:00
CVE Author: NIST National Vulnerability Database (NVD)

CVSS Base Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Solution Type:
Vendor Patch

Detection Type:
Linux Distribution Package

Affected Versions:
openjdk-7 on Debian Linux

Recommendations:
For the oldstable distribution (wheezy), these problems have been fixed in version 7u85-2.6.1-6~deb7u1. For the stable distribution (jessie), these problems have been fixed in version 7u85-2.6.1-5~deb8u1. For the unstable distribution (sid), these problems have been fixed in version 7u85-2.6.1-5. We recommend that you upgrade your openjdk-7 Linux Distribution Packages.

Summary:
Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in the execution of arbitrary code, breakouts of the Java sandbox, information disclosure, or denial of service.

Detection Method:
This check tests the installed software version using the apt Linux Distribution Package manager.

NIST (National Institute of Standards and Technology) NVD (National Vulnerability Database)

https://nvd.nist.gov/vuln/detail/CVE-2015-4734
https://nvd.nist.gov/vuln/detail/CVE-2015-4803
https://nvd.nist.gov/vuln/detail/CVE-2015-4805
https://nvd.nist.gov/vuln/detail/CVE-2015-4806
https://nvd.nist.gov/vuln/detail/CVE-2015-4835
https://nvd.nist.gov/vuln/detail/CVE-2015-4840
https://nvd.nist.gov/vuln/detail/CVE-2015-4842
https://nvd.nist.gov/vuln/detail/CVE-2015-4843
https://nvd.nist.gov/vuln/detail/CVE-2015-4844
https://nvd.nist.gov/vuln/detail/CVE-2015-4860
https://nvd.nist.gov/vuln/detail/CVE-2015-4871
https://nvd.nist.gov/vuln/detail/CVE-2015-4872
https://nvd.nist.gov/vuln/detail/CVE-2015-4881
https://nvd.nist.gov/vuln/detail/CVE-2015-4882
https://nvd.nist.gov/vuln/detail/CVE-2015-4883
https://nvd.nist.gov/vuln/detail/CVE-2015-4893
https://nvd.nist.gov/vuln/detail/CVE-2015-4903
https://nvd.nist.gov/vuln/detail/CVE-2015-4911

References:

http://www.debian.org/security/2015/dsa-3381.html

Search
Severity
High
CVSS Score
10.0

You never have to pay for a vulnerability scanning and management software again.

Tired of paying a subscription 'per asset' or 'per IP'? Well you can officially cancel your current subscription. Mageni provides a free, open source and enterprise-ready vulnerability scanning and management platform which helps you to find, prioritize, remediate and manage your vulnerabilities. It is free and always will be.