Bug 1602142 (CVE-2018-2964) - CVE-2018-2964 Oracle JDK: unspecified vulnerability fixed in 8u181 and 10.0.2 (Deployment)
Summary: CVE-2018-2964 Oracle JDK: unspecified vulnerability fixed in 8u181 and 10.0.2...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2018-2964
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1602113 1602114 1602115
Blocks: 1594250
TreeView+ depends on / blocked
 
Reported: 2018-07-17 21:07 UTC by Tomas Hoger
Modified: 2021-02-16 23:58 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-07-26 10:22:16 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:2253 0 None None None 2018-07-24 21:13:09 UTC
Red Hat Product Errata RHSA-2018:2256 0 None None None 2018-07-24 21:09:35 UTC

Description Tomas Hoger 2018-07-17 21:07:06 UTC
Oracle Java SE 8u181 and 10.0.2 fixes an unspecified vulnerability in the Deployment component (CVE-2018-2964).  Upstream has CVSS scored this issue as: 8.3/CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

External Reference:

http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html#AppendixJAVA

Comment 1 errata-xmlrpc 2018-07-24 21:09:30 UTC
This issue has been addressed in the following products:

  Oracle Java for Red Hat Enterprise Linux 6

Via RHSA-2018:2256 https://access.redhat.com/errata/RHSA-2018:2256

Comment 2 errata-xmlrpc 2018-07-24 21:13:04 UTC
This issue has been addressed in the following products:

  Oracle Java for Red Hat Enterprise Linux 7

Via RHSA-2018:2253 https://access.redhat.com/errata/RHSA-2018:2253

Comment 3 Tomas Hoger 2018-07-26 10:22:16 UTC
Note that IBM notes this issue as "Applicable on Windows Only" for their IBM JDK:

https://developer.ibm.com/javasdk/support/security-vulnerabilities/#Oracle_July_17_2018_CPU

It is possible the same applies to Oracle JDK, however Oracle has not published further details about this flaw.


Note You need to log in before you can comment on or make changes to this bug.