SCIENTIFIC-LINUX-ERRATA Archives

January 2015

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Wed, 21 Jan 2015 16:47:57 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (95 lines)
Synopsis:          Important: java-1.8.0-openjdk security update
Advisory ID:       SLSA-2015:0069-1
Issue Date:        2015-01-21
CVE Numbers:       CVE-2014-3566
                   CVE-2015-0383
                   CVE-2014-6601
                   CVE-2015-0412
                   CVE-2015-0408
                   CVE-2015-0395
                   CVE-2015-0407
                   CVE-2015-0410
                   CVE-2014-6593
                   CVE-2014-6585
                   CVE-2014-6591
                   CVE-2014-6587
                   CVE-2014-6549
                   CVE-2015-0437
--

Multiple flaws were found in the way the Hotspot component in OpenJDK
verified bytecode from the class files, and in the way this component
generated code for bytecode. An untrusted Java application or applet could
possibly use these flaws to bypass Java sandbox restrictions.
(CVE-2014-6601, CVE-2015-0437)

Multiple improper permission check issues were discovered in the JAX-WS,
Libraries, and RMI components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass Java sandbox restrictions.
(CVE-2015-0412, CVE-2014-6549, CVE-2015-0408)

A flaw was found in the way the Hotspot garbage collector handled phantom
references. An untrusted Java application or applet could use this flaw to
corrupt the Java Virtual Machine memory and, possibly, execute arbitrary
code, bypassing Java sandbox restrictions. (CVE-2015-0395)

A flaw was found in the way the DER (Distinguished Encoding Rules) decoder
in the Security component in OpenJDK handled negative length values. A
specially crafted, DER-encoded input could cause a Java application to
enter an infinite loop when decoded. (CVE-2015-0410)

A flaw was found in the way the SSL 3.0 protocol handled padding bytes
when decrypting messages that were encrypted using block ciphers in cipher
block chaining (CBC) mode. This flaw could possibly allow a man-in-the-
middle (MITM) attacker to decrypt portions of the cipher text using a
padding oracle attack. (CVE-2014-3566)

It was discovered that the SSL/TLS implementation in the JSSE component in
OpenJDK failed to properly check whether the ChangeCipherSpec was received
during the SSL/TLS connection handshake. An MITM attacker could possibly
use this flaw to force a connection to be established without encryption
being enabled. (CVE-2014-6593)

An information leak flaw was found in the Swing component in OpenJDK. An
untrusted Java application or applet could use this flaw to bypass certain
Java sandbox restrictions. (CVE-2015-0407)

A NULL pointer dereference flaw was found in the MulticastSocket
implementation in the Libraries component of OpenJDK. An untrusted Java
application or applet could possibly use this flaw to bypass certain Java
sandbox restrictions. (CVE-2014-6587)

Multiple boundary check flaws were found in the font parsing code in the
2D component in OpenJDK. A specially crafted font file could allow an
untrusted Java application or applet to disclose portions of the Java
Virtual Machine memory. (CVE-2014-6585, CVE-2014-6591)

Multiple insecure temporary file use issues were found in the way the
Hotspot component in OpenJDK created performance statistics and error log
files. A local attacker could possibly make a victim using OpenJDK
overwrite arbitrary files using a symlink attack. (CVE-2015-0383)

All running instances of OpenJDK Java must be restarted for the update to
take effect.
--

SL6
  x86_64
    java-1.8.0-openjdk-1.8.0.31-1.b13.el6_6.x86_64.rpm
    java-1.8.0-openjdk-debuginfo-1.8.0.31-1.b13.el6_6.x86_64.rpm
    java-1.8.0-openjdk-demo-1.8.0.31-1.b13.el6_6.x86_64.rpm
    java-1.8.0-openjdk-devel-1.8.0.31-1.b13.el6_6.x86_64.rpm
    java-1.8.0-openjdk-headless-1.8.0.31-1.b13.el6_6.x86_64.rpm
    java-1.8.0-openjdk-javadoc-1.8.0.31-1.b13.el6_6.noarch.rpm
    java-1.8.0-openjdk-src-1.8.0.31-1.b13.el6_6.x86_64.rpm
  i386
    java-1.8.0-openjdk-1.8.0.31-1.b13.el6_6.i686.rpm
    java-1.8.0-openjdk-debuginfo-1.8.0.31-1.b13.el6_6.i686.rpm
    java-1.8.0-openjdk-demo-1.8.0.31-1.b13.el6_6.i686.rpm
    java-1.8.0-openjdk-devel-1.8.0.31-1.b13.el6_6.i686.rpm
    java-1.8.0-openjdk-headless-1.8.0.31-1.b13.el6_6.i686.rpm
    java-1.8.0-openjdk-javadoc-1.8.0.31-1.b13.el6_6.noarch.rpm
    java-1.8.0-openjdk-src-1.8.0.31-1.b13.el6_6.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2