JPCERT-AT-2018-0003
JPCERT/CC
2018-01-17
It is recommended to update the software to the latest version provided by Oracle:
Oracle Critical Patch Update Advisory - January 2018
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
- Java SE JDK/JRE 8 Update 152 and earlier
- Java SE JKD/JRE 9.0.1 and earlier
* According to Oracle, Java SE JDK / JRE 6 and 7, which had already
ended Public Updates, are also affected by these vulnerabilities.
* PCs provided by some certain manufacturers may have JRE pre-installed.
Please check the PC that you are using for any installed versions
of JRE.
- Java SE JDK/JRE 8 Update 161
- Java SE JDK/JRE 9.0.4
* For this Java SE JDK/JRE 8 Update, a patch set update (8u162),
including all of 8u161 plus additional features is available for
developers and users. Please consider updating to 8u162.
Java SE Downloads
http://www.oracle.com/technetwork/java/javase/downloads/index.html
Free Java Download
https://java.com/en/download/
Users of 64-bit Windows may have 32-bit and/or 64-bit versions of JDK/JRE installed. Please check the versions installed on your system and apply the appropriate updates.
Users can check the version of Java that they are using at the page below. If both 32-bit and 64-bit versions of Java are installed,please check the versions installed, using a 32-bit and 64-bit browser respectively. (In environments where Java is not installed, there may be a request to install Java. If you do not require Java, please do not install.)
Verify Java and Find Out-of-Date Versions
https://www.java.com/en/download/installed.jsp
* Some applications that use Java may not run properly after updating
Java to the latest version. Please update to the latest version
after considering any possible impacts to applications that you
may use.
Oracle Corporation
Oracle Critical Patch Update Advisory - January 2018
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
Oracle Corporation
Release Notes for JDK 8 and JDK 8 Update Releases
http://www.oracle.com/technetwork/java/javase/8all-relnotes-2226344.html
Oracle Corporation
Release Notes for JDK 9 and JDK 9 Update Releases
http://www.oracle.com/technetwork/java/javase/9all-relnotes-3704433.html
Oracle Corporation
Oracle Java SE Support Roadmap
http://www.oracle.com/technetwork/java/eol-135779.html
US-CERT
Oracle Releases January 2018 Security Bulletin
https://www.us-cert.gov/ncas/current-activity/2018/01/16/Oracle-Releases-January-2018-Security-Bulletin
If you have any information regarding this alert, please contact JPCERT/CC.
JPCERT Coordination Center (JPCERT/CC)
MAIL: info@jpcert.or.jp
TEL: +81-3-3518-4600 FAX: +81-3-3518-4602
https://www.jpcert.or.jp/english/
JPCERT/CC
2018-01-17
I. Overview
Java SE JDK and JRE provided by Oracle contain multiple vulnerabilities.A remote attacker may cause Java to crash or execute arbitrary code by leveraging these vulnerabilities. For more information on the vulnerabilities, please refer to the information provided by Oracle.It is recommended to update the software to the latest version provided by Oracle:
Oracle Critical Patch Update Advisory - January 2018
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
II. Affected Products
The following products and versions are affected by these vulnerabilities:- Java SE JDK/JRE 8 Update 152 and earlier
- Java SE JKD/JRE 9.0.1 and earlier
* According to Oracle, Java SE JDK / JRE 6 and 7, which had already
ended Public Updates, are also affected by these vulnerabilities.
* PCs provided by some certain manufacturers may have JRE pre-installed.
Please check the PC that you are using for any installed versions
of JRE.
III. Solution
Oracle has released an update. Please update the software to the latest version.- Java SE JDK/JRE 8 Update 161
- Java SE JDK/JRE 9.0.4
* For this Java SE JDK/JRE 8 Update, a patch set update (8u162),
including all of 8u161 plus additional features is available for
developers and users. Please consider updating to 8u162.
Java SE Downloads
http://www.oracle.com/technetwork/java/javase/downloads/index.html
Free Java Download
https://java.com/en/download/
Users of 64-bit Windows may have 32-bit and/or 64-bit versions of JDK/JRE installed. Please check the versions installed on your system and apply the appropriate updates.
Users can check the version of Java that they are using at the page below. If both 32-bit and 64-bit versions of Java are installed,please check the versions installed, using a 32-bit and 64-bit browser respectively. (In environments where Java is not installed, there may be a request to install Java. If you do not require Java, please do not install.)
Verify Java and Find Out-of-Date Versions
https://www.java.com/en/download/installed.jsp
* Some applications that use Java may not run properly after updating
Java to the latest version. Please update to the latest version
after considering any possible impacts to applications that you
may use.
IV. References
Oracle Corporation
Oracle Critical Patch Update Advisory - January 2018
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
Oracle Corporation
Release Notes for JDK 8 and JDK 8 Update Releases
http://www.oracle.com/technetwork/java/javase/8all-relnotes-2226344.html
Oracle Corporation
Release Notes for JDK 9 and JDK 9 Update Releases
http://www.oracle.com/technetwork/java/javase/9all-relnotes-3704433.html
Oracle Corporation
Oracle Java SE Support Roadmap
http://www.oracle.com/technetwork/java/eol-135779.html
US-CERT
Oracle Releases January 2018 Security Bulletin
https://www.us-cert.gov/ncas/current-activity/2018/01/16/Oracle-Releases-January-2018-Security-Bulletin
If you have any information regarding this alert, please contact JPCERT/CC.
JPCERT Coordination Center (JPCERT/CC)
MAIL: info@jpcert.or.jp
TEL: +81-3-3518-4600 FAX: +81-3-3518-4602
https://www.jpcert.or.jp/english/