Red Hat Security Advisory: java-1.7.0-openjdk security and bug fix update
🔗 CVE IDs covered (10)
📋 Description
CVE-2014-6457 — OpenJDK: Triple Handshake attack against TLS/SSL connections (JSSE, 8037066) CVE-2014-6502 — OpenJDK: LogRecord use of incorrect CL when loading ResourceBundle (Libraries, 8042797) CVE-2014-6504 — OpenJDK: incorrect optimization of range checks in C2 compiler (Hotspot, 8022783) CVE-2014-6506 — OpenJDK: insufficient permission checks when setting resource bundle on system logger (Libraries, 8041564) CVE-2014-6511 — ICU: Layout Engine ContextualSubstitution missing boundary checks (JDK 2D, 8041540) CVE-2014-6512 — OpenJDK: DatagramSocket connected socket missing source check (Libraries, 8039509) CVE-2014-6517 — OpenJDK: StAX parser parameter entity XXE (JAXP, 8039533) CVE-2014-6519 — OpenJDK: missing BootstrapMethods bounds check (Hotspot, 8041717) CVE-2014-6531 — OpenJDK: insufficient ResourceBundle name check (Libraries, 8044274) CVE-2014-6558 — OpenJDK: CipherInputStream incorrect exception handling (Security, 8037846)
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2014:1620
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1071210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1148309
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1150155
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1150182
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1150273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1150651
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1150669
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1151046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1151063
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1151364
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1151517
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2014/rhsa-2014_1620.json