Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1152049 - (CVE-2014-6468) CVE-2014-6468 OpenJDK: insufficient SharedArchiveFile checks (Hotspot, 8044269)
CVE-2014-6468 OpenJDK: insufficient SharedArchiveFile checks (Hotspot, 8044269)
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20141014,reported=2...
: Security
Depends On:
Blocks: 1148726
  Show dependency treegraph
 
Reported: 2014-10-13 08:12 EDT by Tomas Hoger
Modified: 2014-11-05 04:26 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
It was discovered that the Hotspot component in OpenJDK failed to properly handle malformed Shared Archive files. A local attacker able to modify a Shared Archive file used by a virtual machine of a different user could possibly use this flaw to escalate their privileges.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-10-17 05:26:12 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:1636 normal SHIPPED_LIVE Important: java-1.8.0-openjdk security update 2014-10-15 03:03:25 EDT

  None (edit)
Description Tomas Hoger 2014-10-13 08:12:39 EDT
It was discovered that the Hotspot component in OpenJDK failed to properly check the format of a loaded SharedArchiveFile.  If a JVM was instructed to load untrusted SharedArchiveFile, it could cause JVM to execute arbitrary code.

OpenJDK versions 6 and 7 only load shared archive that is distributed with JDK and the file path is hard-coded in JVM.  OpenJDK 8 allows alternate shared archive file name to be specified using the -XX:SharedArchiveFile= command line option.
Comment 2 Tomas Hoger 2014-10-14 16:15:08 EDT
Public now via Oracle Critical Patch Update - October 2014.  Fixed in Oracle Java SE 8u25.

External References:

http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html#AppendixJAVA
Comment 3 errata-xmlrpc 2014-10-14 23:03:47 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2014:1636 https://rhn.redhat.com/errata/RHSA-2014-1636.html
Comment 4 Martin Prpič 2014-10-15 05:40:16 EDT
IssueDescription:

It was discovered that the Hotspot component in OpenJDK failed to properly handle malformed Shared Archive files. A local attacker able to modify a Shared Archive file used by a virtual machine of a different user could possibly use this flaw to escalate their privileges.
Comment 6 Tomas Hoger 2014-11-05 04:26:06 EST
The Oracle October 2014 CPU was updated to use the following note for this issue:

  Applies to client and server deployment of Java. This vulnerability requires
  local access to the victim environment in order to plant the affected jar
  file. Once the affected jar file was planted, this vulnerability can be
  triggered through sandboxed Java Web Start applications, sandboxed Java
  applets, and launching the affected application locally. It can also be
  triggered by supplying data to APIs in the specified component without using
  sandboxed Java Web Start applications or sandboxed Java applets, such as
  through a web service.

Note You need to log in before you can comment on or make changes to this bug.