CVE-2014-0424: High severity ORACLE JRE vulnerability
Oracle Java SE 6u71 and 7u51 fixes an unspecified vulnerability in the Deployment component (CVE-2014-0424). Upstream has CVSSv2 scored this issue as: 7.5/AV:N/AC:L/Au:N/C:P/I:P/A:P
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html#AppendixJAVA
Other sources
Unspecified vulnerability in Oracle Java SE 6u65 and 7u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-5889, CVE-2013-5902, CVE-2014-0410, CVE-2014-0415, and CVE-2014-0418.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-sun-1:1.6.0.75-1jpp.3.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-sun-1:1.6.0.75-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-oracle-1:1.7.0.51-1jpp.1.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-ibm-1:1.7.0.6.1-1jpp.1.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.15.1-1jpp.1.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-oracle-1:1.7.0.51-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-ibm-1:1.7.0.6.1-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.15.1-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.1-ibm-1:1.7.1.1.0-1jpp.2.el7_0 - Upgrade
Upgrade
Oracle Java SE Deployment componentto a version that resolves this vulnerability.Fixed in 6u71 - Upgrade
Upgrade
Oracle Java SE Deployment componentto a version that resolves this vulnerability.Fixed in 7u51 - Upgrade
Upgrade
Oracle Java SE Deployment componentto a version that resolves this vulnerability.Fixed in 6u65 - Upgrade
Upgrade
Oracle Java SE Deployment componentto a version that resolves this vulnerability.Fixed in 7u45
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2014-0424?
CVE-2014-0424 has a CVSSv2 score of 7.5, indicating it is a high severity vulnerability.
How do I fix CVE-2014-0424?
To fix CVE-2014-0424, update to the latest version of the affected Java packages indicated in the security advisory.
Which versions of Java are affected by CVE-2014-0424?
CVE-2014-0424 affects Oracle JDK and JRE versions 1.6.0 update 71 and 1.7.0 update 51.
What component is impacted by CVE-2014-0424?
CVE-2014-0424 impacts the Deployment component of Oracle Java.
Is CVE-2014-0424 being exploited in the wild?
There have been reported instances of CVE-2014-0424 being exploited, making it critical to apply patches promptly.