CVE-2014-0418: Medium severity redhat Enterprise Linux Desktop Supplementary vulnerability
Oracle Java SE 6u71 and 7u51 fixes an unspecified vulnerability in the Deployment component (CVE-2014-0418). Upstream has CVSSv2 scored this issue as: 5.1/AV:N/AC:H/Au:N/C:P/I:P/A:P
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html#AppendixJAVA
Other sources
Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, and CVE-2014-0424.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-sun-1:1.6.0.75-1jpp.3.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-sun-1:1.6.0.75-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-oracle-1:1.7.0.51-1jpp.1.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-oracle-1:1.7.0.51-1jpp.1.el6_5 - Upgrade
Upgrade
Oracle Java SE Deployment component (Java SE 6/7)to a version that resolves this vulnerability.Fixed in 6u71 - Upgrade
Upgrade
Oracle Java SE Deployment component (Java SE 6/7)to a version that resolves this vulnerability.Fixed in 7u51 - Upgrade
Upgrade
Oracle Java SE Deployment component (Java SE 6/7)to a version that resolves this vulnerability.Fixed in 6u65 - Upgrade
Upgrade
Oracle Java SE Deployment component (Java SE 6/7)to a version that resolves this vulnerability.Fixed in 7u45
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2014-0418?
CVE-2014-0418 has a CVSSv2 score of 5.1, indicating medium severity.
How do I fix CVE-2014-0418?
To fix CVE-2014-0418, update Oracle Java to version 6u71 or 7u51 or later.
Which versions of Java are affected by CVE-2014-0418?
CVE-2014-0418 affects Oracle Java SE versions 6u71 and 7u51.
Is CVE-2014-0418 a critical vulnerability?
CVE-2014-0418 is not classified as critical but is still important to address promptly.
What components are impacted by CVE-2014-0418?
CVE-2014-0418 impacts the Deployment component of Oracle Java.