CVE-2017-10345 -- openjdk-9-jdk, openjdk-6-jdkDeprecated |
ID: oval:org.secpod.oval:def:1900180 | Date: (C)2019-03-22 (M)2023-12-26 |
Class: VULNERABILITY | Family: unix |
Francesco Palmarini, Marco Squarcina, Mauro Tempesta, and RiccardoFocardi discovered that the Serialization component of OpenJDK did not properly restrict the amount of memory allocated when deserializingobjects from Java Cryptography Extension KeyStore . An attacker could use this to cause a denial of service .
Platform: |
Ubuntu 16.04 |
Ubuntu 14.04 |
Product: |
openjdk-9-jdk |
openjdk-6-jdk |