Red Hat Security Advisory: java-1.7.1-ibm security update
🔗 CVE IDs covered (15)
📋 Description
CVE-2014-3068 — JDK: Java CMS keystore provider potentially allows brute-force private key recovery CVE-2014-3086 — JDK: Privilege escalation issue CVE-2014-4208 — JDK: unspecified vulnerability fixed in 7u65 and 8u11 (Deployment) CVE-2014-4209 — OpenJDK: SubjectDelegator protection insufficient (JMX, 8029755) CVE-2014-4218 — OpenJDK: Clone interfaces passed to proxy methods (Libraries, 8035009) CVE-2014-4219 — OpenJDK: Bytecode verification does not prevent ctor calls to this() and super() (Hotspot, 8035119) CVE-2014-4220 — JDK: unspecified vulnerability fixed in 7u65 and 8u11 (Deployment) CVE-2014-4221 — OpenJDK: MethodHandles.Lookup insufficient modifiers checks (Libraries, 8035788) CVE-2014-4227 — JDK: unspecified vulnerability fixed in 6u81, 7u65 and 8u11 (Deployment) CVE-2014-4244 — OpenJDK: RSA blinding issues (Security, 8031346) CVE-2014-4252 — OpenJDK: Prevent instantiation of service with non-public constructor (Security, 8035004) CVE-2014-4262 — OpenJDK: AtomicReferenceFieldUpdater missing primitive type check (Libraries, 8039520) CVE-2014-4263 — OpenJDK: insufficient Diffie-Hellman public key validation (Security, 8037162) CVE-2014-4265 — JDK: unspecified vulnerability fixed in 6u81, 7u65 and 8u11 (Deployment) CVE-2014-4266 — OpenJDK: InfoBuilder incorrect return values (Serviceability, 8033301)
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2014:1042
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://www.ibm.com/developerworks/java/jdk/alerts/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1075795
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1119475
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1119476
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1119483
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1119596
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1119608
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1119611
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1119613
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1119615
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1119912
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1119913
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1119914
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1119915
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2014/rhsa-2014_1042.json