Gentoo Archives: gentoo-announce

From: "Christopher Díaz Riveros" <chrisadr@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201711-14 ] IcedTea: Multiple vulnerabilities
Date: Sun, 19 Nov 2017 20:37:01
Message-Id: 1511123709.29347.50.camel@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory                           GLSA 201711-14
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4                                            https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7  Severity: Normal
8     Title: IcedTea: Multiple vulnerabilities
9      Date: November 19, 2017
10      Bugs: #636522
11        ID: 201711-14
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in IcedTea, the worst of which
19 may allow execution of arbitrary code.
20
21 Background
22 ==========
23
24 IcedTea’s aim is to provide OpenJDK in a form suitable for easy
25 configuration, compilation and distribution with the primary goal of
26 allowing inclusion in GNU/Linux distributions.
27
28 Affected packages
29 =================
30
31     -------------------------------------------------------------------
32      Package              /     Vulnerable     /            Unaffected
33     -------------------------------------------------------------------
34   1  dev-java/icedtea-bin         < 3.6.0                    >= 3.6.0 
35
36 Description
37 ===========
38
39 Multiple vulnerabilities have been discovered in IcedTea. Please review
40 the referenced CVE identifiers for details.
41
42 Impact
43 ======
44
45 A remote attacker could possibly execute arbitrary code with the
46 privileges of the process, cause a Denial of Service condition, or gain
47 access to information.
48
49 Workaround
50 ==========
51
52 There is no known workaround at this time.
53
54 Resolution
55 ==========
56
57 All IcedTea binary users should upgrade to the latest version:
58
59   # emerge --sync
60   # emerge --ask --oneshot --verbose ">=dev-java/icedtea-bin-3.6.0"
61
62 References
63 ==========
64
65 [  1 ] CVE-2017-10274
66        https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10274
67 [  2 ] CVE-2017-10281
68        https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10281
69 [  3 ] CVE-2017-10285
70        https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10285
71 [  4 ] CVE-2017-10295
72        https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10295
73 [  5 ] CVE-2017-10345
74        https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10345
75 [  6 ] CVE-2017-10346
76        https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10346
77 [  7 ] CVE-2017-10347
78        https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10347
79 [  8 ] CVE-2017-10348
80        https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10348
81 [  9 ] CVE-2017-10349
82        https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10349
83 [ 10 ] CVE-2017-10350
84        https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10350
85 [ 11 ] CVE-2017-10355
86        https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10355
87 [ 12 ] CVE-2017-10356
88        https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10356
89 [ 13 ] CVE-2017-10357
90        https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10357
91 [ 14 ] CVE-2017-10388
92        https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-10388
93
94 Availability
95 ============
96
97 This GLSA and any updates to it are available for viewing at
98 the Gentoo Security Website:
99
100  https://security.gentoo.org/glsa/201711-14
101
102 Concerns?
103 =========
104
105 Security is a primary focus of Gentoo Linux and ensuring the
106 confidentiality and security of our users' machines is of utmost
107 importance to us. Any security concerns should be addressed to
108 security@g.o or alternatively, you may file a bug at
109 https://bugs.gentoo.org.
110
111 License
112 =======
113
114 Copyright 2017 Gentoo Foundation, Inc; referenced text
115 belongs to its owner(s).
116
117 The contents of this document are licensed under the
118 Creative Commons - Attribution / Share Alike license.
119
120 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature