Related Vulnerabilities: CVE-2017-10176  

It was discovered that the Elliptic Curve (EC) cryptography implementation in the Security component of OpenJDK did not perform computations for certain points correctly. An attacker able to interact with a Java application using EC cryptography could possibly use this flaw to obtain information about the used key.

Severity Medium

Remote Yes

Type Private key recovery

Description

It was discovered that the Elliptic Curve (EC) cryptography implementation in the Security component of OpenJDK did not perform computations for certain points correctly.  An attacker able to interact with a Java application using EC cryptography could possibly use this flaw to obtain information about the used key.

AVG-380 jdk7-openjdk 7.u131_2.6.9-1 7.u151_2.6.11-1 Critical Fixed

12 Aug 2017 ASA-201708-8 AVG-380 jdk7-openjdk Critical multiple issues

http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/d99101781d7e