PT-2014-1232 · Oracle+6 · Oracle Java Se+9

Publicado

2014-01-15

·

Atualizado

2024-06-15

·

CVE-2014-0411

CVSS v2.0

4.0

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 5.0u55, 6u65, and 7u45 JRockit versions R27.7.7 and R28.2.9 Java SE Embedded version 7u45 OpenJDK version 7
Description The issue affects confidentiality and integrity via vectors related to JSSE, allowing remote attackers to exploit it. There are claims that this issue allows remote attackers to obtain sensitive information about encryption keys via a timing discrepancy during the TLS/SSL handshake. The vulnerability is related to subcomponents of the Java Runtime Environment and the Java Development Kit, specifically the JSSE subcomponent.
Recommendations For Oracle Java SE versions 5.0u55, 6u65, and 7u45, consider updating to a newer version to mitigate the risk. For JRockit versions R27.7.7 and R28.2.9, consider updating to a newer version to mitigate the risk. For Java SE Embedded version 7u45, consider updating to a newer version to mitigate the risk. For OpenJDK version 7, consider updating to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the JSSE subcomponent until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2014-00431
BDU:2014-00432
BDU:2014-00433
CESA-2014_0026
CESA-2014_0097
CVE-2014-0411
HPSBUX02972
HPSBUX02973
MGASA-2014-0023
OPENSUSE-SU-2024:10534-1
RHSA-2014:0026
RHSA-2014:0027
RHSA-2014:0030
RHSA-2014:0097
RHSA-2014:0134
RHSA-2014:0135
RHSA-2014:0136
RHSA-2014:0414
RHSA-2014:0705
RHSA-2014:0982
RHSA-2014_0026
RHSA-2014_0027
RHSA-2014_0030
RHSA-2014_0097
RHSA-2014_0134
RHSA-2014_0135
RHSA-2014_0136
RHSA-2014_0414
RHSA-2014_0705

Produtos afetados

Centos
Hp-Ux
Ibm Aix
Jrockit
Java Platform
Java Se Embedded
Openjdk
Oracle Java Se
Red Hat
Suse