{
  "threat_severity" : "Critical",
  "public_date" : "2016-10-18T00:00:00Z",
  "bugzilla" : {
    "description" : "OpenJDK: incomplete type checks of System.arraycopy arguments (Hotspot, 8160591)",
    "id" : "1385402",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1385402"
  },
  "cvss" : {
    "cvss_base_score" : "6.8",
    "cvss_scoring_vector" : "AV:N/AC:M/Au:N/C:P/I:P/A:P",
    "status" : "verified"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.8",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-843",
  "details" : [ "Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot, a different vulnerability than CVE-2016-5573.", "It was discovered that the Hotspot component of OpenJDK did not properly check arguments of the System.arraycopy() function in certain cases. An untrusted Java application or applet could use this flaw to corrupt virtual machine's memory and completely bypass Java sandbox restrictions." ],
  "affected_release" : [ {
    "product_name" : "Oracle Java for Red Hat Enterprise Linux 5",
    "release_date" : "2016-10-20T00:00:00Z",
    "advisory" : "RHSA-2016:2089",
    "cpe" : "cpe:/a:redhat:rhel_extras_oracle_java:5",
    "package" : "java-1.7.0-oracle-1:1.7.0.121-1jpp.1.el5_11"
  }, {
    "product_name" : "Oracle Java for Red Hat Enterprise Linux 5",
    "release_date" : "2016-10-20T00:00:00Z",
    "advisory" : "RHSA-2016:2090",
    "cpe" : "cpe:/a:redhat:rhel_extras_oracle_java:5",
    "package" : "java-1.6.0-sun-1:1.6.0.131-1jpp.1.el5_11"
  }, {
    "product_name" : "Oracle Java for Red Hat Enterprise Linux 6",
    "release_date" : "2016-10-20T00:00:00Z",
    "advisory" : "RHSA-2016:2088",
    "cpe" : "cpe:/a:redhat:rhel_extras_oracle_java:6",
    "package" : "java-1.8.0-oracle-1:1.8.0.111-1jpp.4.el6_8"
  }, {
    "product_name" : "Oracle Java for Red Hat Enterprise Linux 6",
    "release_date" : "2016-10-20T00:00:00Z",
    "advisory" : "RHSA-2016:2089",
    "cpe" : "cpe:/a:redhat:rhel_extras_oracle_java:6",
    "package" : "java-1.7.0-oracle-1:1.7.0.121-1jpp.1.el6_8"
  }, {
    "product_name" : "Oracle Java for Red Hat Enterprise Linux 6",
    "release_date" : "2016-10-20T00:00:00Z",
    "advisory" : "RHSA-2016:2090",
    "cpe" : "cpe:/a:redhat:rhel_extras_oracle_java:6",
    "package" : "java-1.6.0-sun-1:1.6.0.131-1jpp.1.el6_8"
  }, {
    "product_name" : "Oracle Java for Red Hat Enterprise Linux 7",
    "release_date" : "2016-10-20T00:00:00Z",
    "advisory" : "RHSA-2016:2088",
    "cpe" : "cpe:/a:redhat:rhel_extras_oracle_java:7",
    "package" : "java-1.8.0-oracle-1:1.8.0.111-1jpp.4.el7"
  }, {
    "product_name" : "Oracle Java for Red Hat Enterprise Linux 7",
    "release_date" : "2016-10-20T00:00:00Z",
    "advisory" : "RHSA-2016:2089",
    "cpe" : "cpe:/a:redhat:rhel_extras_oracle_java:7",
    "package" : "java-1.7.0-oracle-1:1.7.0.121-1jpp.1.el7"
  }, {
    "product_name" : "Oracle Java for Red Hat Enterprise Linux 7",
    "release_date" : "2016-10-20T00:00:00Z",
    "advisory" : "RHSA-2016:2090",
    "cpe" : "cpe:/a:redhat:rhel_extras_oracle_java:7",
    "package" : "java-1.6.0-sun-1:1.6.0.131-1jpp.1.el7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2016-11-07T00:00:00Z",
    "advisory" : "RHSA-2016:2658",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "java-1.7.0-openjdk-1:1.7.0.121-2.6.8.1.el5_11"
  }, {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2017-01-13T00:00:00Z",
    "advisory" : "RHSA-2017:0061",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "java-1.6.0-openjdk-1:1.6.0.41-1.13.13.1.el5_11"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2016-10-19T00:00:00Z",
    "advisory" : "RHSA-2016:2079",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "java-1.8.0-openjdk-1:1.8.0.111-0.b15.el6_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2016-11-07T00:00:00Z",
    "advisory" : "RHSA-2016:2658",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "java-1.7.0-openjdk-1:1.7.0.121-2.6.8.1.el6_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2017-01-13T00:00:00Z",
    "advisory" : "RHSA-2017:0061",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "java-1.6.0-openjdk-1:1.6.0.41-1.13.13.1.el6_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2016-10-19T00:00:00Z",
    "advisory" : "RHSA-2016:2079",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "java-1.8.0-openjdk-1:1.8.0.111-1.b15.el7_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2016-11-07T00:00:00Z",
    "advisory" : "RHSA-2016:2658",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "java-1.7.0-openjdk-1:1.7.0.121-2.6.8.0.el7_3"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2017-01-13T00:00:00Z",
    "advisory" : "RHSA-2017:0061",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "java-1.6.0-openjdk-1:1.6.0.41-1.13.13.1.el7_3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2016-5582\nhttps://nvd.nist.gov/vuln/detail/CVE-2016-5582\nhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html#AppendixJAVA" ],
  "name" : "CVE-2016-5582",
  "csaw" : false
}