Red Hat Security Advisory: java-1.5.0-ibm security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2014-3065 — JDK: privilege escalation via shared class cache CVE-2014-3566 — SSL/TLS: Padding Oracle On Downgraded Legacy Encryption attack CVE-2014-6457 — OpenJDK: Triple Handshake attack against TLS/SSL connections (JSSE, 8037066) CVE-2014-6502 — OpenJDK: LogRecord use of incorrect CL when loading ResourceBundle (Libraries, 8042797) CVE-2014-6506 — OpenJDK: insufficient permission checks when setting resource bundle on system logger (Libraries, 8041564) CVE-2014-6511 — ICU: Layout Engine ContextualSubstitution missing boundary checks (JDK 2D, 8041540) CVE-2014-6512 — OpenJDK: DatagramSocket connected socket missing source check (Libraries, 8039509) CVE-2014-6531 — OpenJDK: insufficient ResourceBundle name check (Libraries, 8044274) CVE-2014-6558 — OpenJDK: CipherInputStream incorrect exception handling (Security, 8037846)
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2014:1881
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://www.ibm.com/developerworks/java/jdk/alerts/
- externalhttps://www-01.ibm.com/support/docview.wss?uid=swg21688165
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1071210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1150155
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1150651
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1150669
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1151046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1151063
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1151517
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1152789
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1162554
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2014/rhsa-2014_1881.json