Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1443252 - (CVE-2017-3526) CVE-2017-3526 OpenJDK: incomplete XML parse tree size enforcement (JAXP, 8169011)
CVE-2017-3526 OpenJDK: incomplete XML parse tree size enforcement (JAXP, 8169...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20170418,repor...
: Security
Depends On:
Blocks: 1438752
  Show dependency treegraph
 
Reported: 2017-04-18 17:51 EDT by Tomas Hoger
Modified: 2017-06-09 05:08 EDT (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
It was found that the JAXP component of OpenJDK failed to correctly enforce parse tree size limits when parsing XML document. An attacker able to make a Java application parse a specially crafted XML document could use this flaw to make it consume an excessive amount of CPU and memory.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2017-05-09 08:42:33 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:1108 normal SHIPPED_LIVE Moderate: java-1.8.0-openjdk security and bug fix update 2017-04-21 02:10:52 EDT
Red Hat Product Errata RHSA-2017:1109 normal SHIPPED_LIVE Moderate: java-1.8.0-openjdk security update 2017-04-20 19:27:18 EDT
Red Hat Product Errata RHSA-2017:1117 normal SHIPPED_LIVE Moderate: java-1.8.0-oracle security update 2017-12-14 15:17:15 EST
Red Hat Product Errata RHSA-2017:1118 normal SHIPPED_LIVE Moderate: java-1.7.0-oracle security update 2017-12-14 14:52:56 EST
Red Hat Product Errata RHSA-2017:1119 normal SHIPPED_LIVE Moderate: java-1.6.0-sun security update 2017-12-14 14:49:13 EST
Red Hat Product Errata RHSA-2017:1204 normal SHIPPED_LIVE Moderate: java-1.7.0-openjdk security update 2017-05-09 10:46:54 EDT

  None (edit)
Description Tomas Hoger 2017-04-18 17:51:57 EDT
It was found that the JAXP (Java API for XML Processing) component of OpenJDK failed to correctly enforce parse tree size limits when parsing XML document.  An attacker able to make a Java application parse a specially crafted XML document could use this flaw to make it consume an excessive amount of CPU and memory.
Comment 1 Tomas Hoger 2017-04-18 18:19:07 EDT
Public now via Oracle CPU April 20167, fixed in Oracle JDK 8u131, 7u141, and 6u151.

External References:

http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html#AppendixJAVA
Comment 2 Tomas Hoger 2017-04-19 07:32:19 EDT
OpenJDK8 upstream commit:

http://hg.openjdk.java.net/jdk8u/jdk8u/jaxp/rev/756b7a2f20cc
Comment 3 errata-xmlrpc 2017-04-20 15:28:19 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2017:1109 https://access.redhat.com/errata/RHSA-2017:1109
Comment 4 errata-xmlrpc 2017-04-20 22:11:59 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2017:1108 https://access.redhat.com/errata/RHSA-2017:1108
Comment 5 errata-xmlrpc 2017-04-24 07:17:53 EDT
This issue has been addressed in the following products:

  Oracle Java for Red Hat Enterprise Linux 7
  Oracle Java for Red Hat Enterprise Linux 6

Via RHSA-2017:1118 https://access.redhat.com/errata/RHSA-2017:1118
Comment 6 errata-xmlrpc 2017-04-24 07:18:49 EDT
This issue has been addressed in the following products:

  Oracle Java for Red Hat Enterprise Linux 7
  Oracle Java for Red Hat Enterprise Linux 6

Via RHSA-2017:1117 https://access.redhat.com/errata/RHSA-2017:1117
Comment 7 errata-xmlrpc 2017-04-24 07:19:38 EDT
This issue has been addressed in the following products:

  Oracle Java for Red Hat Enterprise Linux 7
  Oracle Java for Red Hat Enterprise Linux 6

Via RHSA-2017:1119 https://access.redhat.com/errata/RHSA-2017:1119
Comment 8 errata-xmlrpc 2017-05-09 06:48:11 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6
  Red Hat Enterprise Linux 7

Via RHSA-2017:1204 https://access.redhat.com/errata/RHSA-2017:1204

Note You need to log in before you can comment on or make changes to this bug.