CVE-2014-0422: Critical severity Oracle JDK vulnerability
It was discovered that the Naming / JNDI component of OpenJDK failed to implement required package access checks. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Other sources
Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JNDI. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to missing package access checks in the Naming / JNDI component, which allows attackers to escape the sandbox.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/icedteato a version that resolves this vulnerability.Fixed in 2.4.4 - Upgrade
Upgrade
redhat/icedteato a version that resolves this vulnerability.Fixed in 2.3.13 - Upgrade
Upgrade
redhat/icedteato a version that resolves this vulnerability.Fixed in 1.12.8 - Upgrade
Upgrade
redhat/icedteato a version that resolves this vulnerability.Fixed in 1.13.1 - Upgrade
Upgrade
Java SE (Oracle) / OpenJDK Naming-JNDIto a version that resolves this vulnerability.Fixed in 7u45
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0422?
CVE-2014-0422 is categorized as a high severity vulnerability due to its potential to bypass Java sandbox restrictions.
How do I fix CVE-2014-0422?
To fix CVE-2014-0422, upgrade to the latest versions of the affected packages such as icedtea version 2.4.4 or Oracle Java JRE/JDK updates.
What software is affected by CVE-2014-0422?
CVE-2014-0422 affects Oracle JDK and JRE versions 1.5.0, 1.6.0, and 1.7.0, as well as specific versions of Red Hat's icedtea.
Can CVE-2014-0422 be exploited remotely?
Yes, CVE-2014-0422 can potentially be exploited remotely by untrusted Java applications or applets.
What are the consequences of CVE-2014-0422?
Exploitation of CVE-2014-0422 could allow an attacker to bypass Java security policies, leading to unauthorized access or control over the affected system.