CVE-2016-3443

Impact:
Critical
Public Date:
2016-04-19
Bugzilla:
1328618: CVE-2016-3443 Oracle JDK: unspecified vulnerability fixed in 6u115, 7u101 and 8u91 (2D)

The MITRE CVE dictionary describes this issue as:

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to 2D. NOTE: the previous information is from the April 2016 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information via crafted font data, which triggers an out-of-bounds read.

Find out more about CVE-2016-3443 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 6.8
Base Metrics AV:N/AC:M/Au:N/C:P/I:P/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux Supplementary (v. 7) (java-1.8.0-ibm) RHSA-2016:0716 2016-05-03
Oracle Java for Red Hat Enterprise Linux 7 (java-1.7.0-oracle) RHSA-2016:0678 2016-04-21
Red Hat Satellite 5.6 (RHEL v.6) (java-1.7.1-ibm) RHSA-2017:1216 2017-05-09
Oracle Java for Red Hat Enterprise Linux 6 (java-1.6.0-sun) RHSA-2016:0679 2016-04-21
Red Hat Enterprise Linux Supplementary (v. 7) (java-1.7.1-ibm) RHSA-2016:0701 2016-04-29
Oracle Java for Red Hat Enterprise Linux 6 (java-1.8.0-oracle) RHSA-2016:0677 2016-04-21
Red Hat Enterprise Linux Supplementary (v. 6) (java-1.8.0-ibm) RHSA-2016:1039 2016-05-11
Red Hat Enterprise Linux Supplementary (v. 6) (java-1.7.1-ibm) RHSA-2016:0701 2016-04-29
Oracle Java for Red Hat Enterprise Linux 5 (java-1.6.0-sun) RHSA-2016:0679 2016-04-21
Oracle Java for Red Hat Enterprise Linux 5 (java-1.7.0-oracle) RHSA-2016:0678 2016-04-21
Oracle Java for Red Hat Enterprise Linux 7 (java-1.8.0-oracle) RHSA-2016:0677 2016-04-21
Red Hat Enterprise Linux Supplementary 5 (java-1.7.0-ibm) RHSA-2016:0702 2016-04-29
Red Hat Satellite 5.6 (RHEL v.6) (java-1.7.1-ibm) RHSA-2016:1430 2016-07-18
Oracle Java for Red Hat Enterprise Linux 7 (java-1.6.0-sun) RHSA-2016:0679 2016-04-21
Red Hat Satellite 5.7 (RHEL v.6) (java-1.7.1-ibm) RHSA-2016:1430 2016-07-18
Red Hat Satellite 5.7 (RHEL v.6) (java-1.7.1-ibm) RHSA-2017:1216 2017-05-09
Red Hat Enterprise Linux Supplementary (v. 6) (java-1.6.0-ibm) RHSA-2016:0708 2016-05-02
Red Hat Enterprise Linux Supplementary 5 (java-1.6.0-ibm) RHSA-2016:0708 2016-05-02
Oracle Java for Red Hat Enterprise Linux 6 (java-1.7.0-oracle) RHSA-2016:0678 2016-04-21
Red Hat Satellite 5.6 (RHEL v.5) (java-1.7.0-ibm) RHSA-2016:1430 2016-07-18

External References

Last Modified

CVE description copyright © 2017, The MITRE Corporation