Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3426

Опубликовано: 19 апр. 2016
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.

It was discovered that the GCM (Galois/Counter Mode) implementation in the JCE component in OpenJDK used a non-constant time comparison when comparing GCM authentication tags. A remote attacker could possibly use this flaw to determine the value of the authentication tag.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5java-1.6.0-openjdkNot affected
Red Hat Enterprise Linux 5java-1.7.0-openjdkNot affected
Red Hat Enterprise Linux 6java-1.6.0-openjdkNot affected
Red Hat Enterprise Linux 6java-1.7.0-openjdkNot affected
Red Hat Enterprise Linux 7java-1.6.0-openjdkNot affected
Red Hat Enterprise Linux 7java-1.7.0-openjdkNot affected
Oracle Java for Red Hat Enterprise Linux 6java-1.8.0-oracleFixedRHSA-2016:067721.04.2016
Oracle Java for Red Hat Enterprise Linux 7java-1.8.0-oracleFixedRHSA-2016:067721.04.2016
Red Hat Enterprise Linux 5 Supplementaryjava-1.7.0-ibmFixedRHSA-2016:070229.04.2016
Red Hat Enterprise Linux 5 Supplementaryjava-1.6.0-ibmFixedRHSA-2016:070802.05.2016

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1328059OpenJDK: non-constant time GCM authentication tag comparison (JCE, 8143945)

EPSS

Процентиль: 75%
0.00923
Низкий

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 3.1
ubuntu
больше 9 лет назад

Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.

CVSS3: 3.1
nvd
больше 9 лет назад

Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.

CVSS3: 3.1
debian
больше 9 лет назад

Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded ...

CVSS3: 3.1
github
больше 3 лет назад

Unspecified vulnerability in Oracle Java SE 8u77 and Java SE Embedded 8u77 allows remote attackers to affect confidentiality via vectors related to JCE.

suse-cvrf
больше 9 лет назад

Security update for java-1_8_0-openjdk

EPSS

Процентиль: 75%
0.00923
Низкий

2.6 Low

CVSS2