2018年8月19日 星期日

[USN-3734-1] OpenJDK 8 vulnerability

---------- Forwarded message ----------
From: Steve Beattie 
Date: 2018-08-10 10:12 GMT+08:00

Summary:

Java applications could be made to use excessive memory.

Details:

It was discovered that the PatternSyntaxException class in OpenJDK
did not properly validate arguments passed to it. An attacker could
use this to possibly construct a class that caused a denial of service
(excessive memory consumption).

References:
  https://usn.ubuntu.com/usn/usn-3734-1
  CVE-2018-2952

沒有留言:

張貼留言