CVE-2016-5582
OpenJDK: incomplete type checks of System.arraycopy arguments (Hotspot, 8160591)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.
Vulnerabilidad no especificada en Oracle Java SE 6u121, 7u111, 8u102 y Java SE Embedded 8u101 permite a atacantes remotos afectar la confidencialidad, la integridad y la disponibilidad a través de vectores relacionados con Hotspot, una vulnerabilidad diferente a CVE-2016-5573.
It was discovered that the Hotspot component of OpenJDK did not properly check arguments of the System.arraycopy() function in certain cases. An untrusted Java application or applet could use this flaw to corrupt virtual machine's memory and completely bypass Java sandbox restrictions.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2016-06-16 CVE Reserved
- 2016-10-19 CVE Published
- 2024-08-17 EPSS Updated
- 2024-10-10 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
- CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
CAPEC
References (18)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/93623 | Vdb Entry | |
http://www.securitytracker.com/id/1037040 | Vdb Entry | |
https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E | Mailing List | |
https://security.netapp.com/advisory/ntap-20161019-0001 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html | 2023-11-07 |
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2016-2079.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2016-2088.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2016-2089.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2016-2090.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2016-2658.html | 2023-11-07 | |
http://rhn.redhat.com/errata/RHSA-2017-0061.html | 2023-11-07 | |
http://www.debian.org/security/2016/dsa-3707 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-3130-1 | 2023-11-07 | |
http://www.ubuntu.com/usn/USN-3154-1 | 2023-11-07 | |
https://security.gentoo.org/glsa/201611-04 | 2023-11-07 | |
https://security.gentoo.org/glsa/201701-43 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2016-5582 | 2017-01-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1385402 | 2017-01-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Jdk Search vendor "Oracle" for product "Jdk" | 1.6.0 Search vendor "Oracle" for product "Jdk" and version "1.6.0" | update121 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jdk Search vendor "Oracle" for product "Jdk" | 1.7.0 Search vendor "Oracle" for product "Jdk" and version "1.7.0" | update111 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jdk Search vendor "Oracle" for product "Jdk" | 1.8.0 Search vendor "Oracle" for product "Jdk" and version "1.8.0" | update101 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jdk Search vendor "Oracle" for product "Jdk" | 1.8.0 Search vendor "Oracle" for product "Jdk" and version "1.8.0" | update102 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.6.0 Search vendor "Oracle" for product "Jre" and version "1.6.0" | update121 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.7.0 Search vendor "Oracle" for product "Jre" and version "1.7.0" | update111 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.8.0 Search vendor "Oracle" for product "Jre" and version "1.8.0" | update101 |
Affected
| ||||||
Oracle Search vendor "Oracle" | Jre Search vendor "Oracle" for product "Jre" | 1.8.0 Search vendor "Oracle" for product "Jre" and version "1.8.0" | update102 |
Affected
|