Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1472470 - (CVE-2017-10118) CVE-2017-10118 OpenJDK: ECDSA implementation timing attack (JCE, 8175110)
CVE-2017-10118 OpenJDK: ECDSA implementation timing attack (JCE, 8175110)
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20170718,repor...
: Security
Depends On:
Blocks: 1466515
  Show dependency treegraph
 
Reported: 2017-07-18 16:12 EDT by Tomas Hoger
Modified: 2018-03-04 18:13 EST (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:1790 normal SHIPPED_LIVE Critical: java-1.8.0-oracle security update 2017-12-14 15:16:58 EST
Red Hat Product Errata RHSA-2017:1791 normal SHIPPED_LIVE Critical: java-1.7.0-oracle security update 2017-12-14 14:49:45 EST

  None (edit)
Description Tomas Hoger 2017-07-18 16:12:18 EDT
A covert timing channel flaw was found in the ECDSA implementation in the JCE component of OpenJDK.  A remote attacker able to make a Java application generate ECDSA signatures on demand could possibly use this flaw to extract certain information about the used key via a timing side channel.
Comment 1 Tomas Hoger 2017-07-18 16:51:22 EDT
Public now via Oracle CPU July 2017:

http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixJAVA

The issue was fixed in Oracle JDK 8u141 and 7u151.
Comment 2 Tomas Hoger 2017-07-19 10:43:39 EDT
OpenJDK-8 upstream commit:

http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/996632997de8
Comment 3 errata-xmlrpc 2017-07-20 12:04:06 EDT
This issue has been addressed in the following products:

  Oracle Java for Red Hat Enterprise Linux 7
  Oracle Java for Red Hat Enterprise Linux 6

Via RHSA-2017:1791 https://access.redhat.com/errata/RHSA-2017:1791
Comment 4 errata-xmlrpc 2017-07-20 12:20:01 EDT
This issue has been addressed in the following products:

  Oracle Java for Red Hat Enterprise Linux 7
  Oracle Java for Red Hat Enterprise Linux 6

Via RHSA-2017:1790 https://access.redhat.com/errata/RHSA-2017:1790

Note You need to log in before you can comment on or make changes to this bug.