Red Hat Security Advisory: java-1.7.1-ibm security update
🔗 CVE IDs covered (19)
📋 Description
CVE-2014-3065 — JDK: privilege escalation via shared class cache CVE-2014-3566 — SSL/TLS: Padding Oracle On Downgraded Legacy Encryption attack CVE-2014-4288 — JDK: unspecified vulnerability fixed in 6u85, 7u71 and 8u25 (Deployment) CVE-2014-6456 — JDK: unspecified vulnerability fixed in 7u71 and 8u25 (Deployment) CVE-2014-6457 — OpenJDK: Triple Handshake attack against TLS/SSL connections (JSSE, 8037066) CVE-2014-6458 — JDK: unspecified vulnerability fixed in 6u85, 7u71 and 8u25 (Deployment) CVE-2014-6476 — JDK: unspecified vulnerability fixed in 7u71 and 8u25 (Deployment) CVE-2014-6492 — JDK: unspecified vulnerability fixed in 6u85, 7u71 and 8u25 (Deployment) CVE-2014-6493 — JDK: unspecified vulnerability fixed in 6u85, 7u71 and 8u25 (Deployment) CVE-2014-6502 — OpenJDK: LogRecord use of incorrect CL when loading ResourceBundle (Libraries, 8042797) CVE-2014-6503 — JDK: unspecified vulnerability fixed in 6u85, 7u71 and 8u25 (Deployment) CVE-2014-6506 — OpenJDK: insufficient permission checks when setting resource bundle on system logger (Libraries, 8041564) CVE-2014-6511 — ICU: Layout Engine ContextualSubstitution missing boundary checks (JDK 2D, 8041540) CVE-2014-6512 — OpenJDK: DatagramSocket connected socket missing source check (Libraries, 8039509) CVE-2014-6515 — JDK: unspecified vulnerability fixed in 6u85, 7u71 and 8u25 (Deployment) CVE-2014-6527 — JDK: unspecified vulnerability fixed in 7u71 and 8u25 (Deployment) CVE-2014-6531 — OpenJDK: insufficient ResourceBundle name check (Libraries, 8044274) CVE-2014-6532 — JDK: unspecified vulnerability fixed in 6u85, 7u71 and 8u25 (Deployment) CVE-2014-6558 — OpenJDK: CipherInputStream incorrect exception handling (Security, 8037846)
🔗 References (24)
- selfhttps://access.redhat.com/errata/RHSA-2014:1880
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://www.ibm.com/developerworks/java/jdk/alerts/
- externalhttps://www-01.ibm.com/support/docview.wss?uid=swg21688165
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1071210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1150155
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1150651
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1150669
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1151046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1151063
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1151517
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1152756
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1152757
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1152758
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1152759
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1152760
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1152761
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1152763
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1152765
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1152766
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1152767
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1152789
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1162554
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2014/rhsa-2014_1880.json