First published: Fri Apr 11 2014(Updated: )
It was discovered that the Security component in OpenJDK could leak some timing information when preforming PKCS#1 unpadding. This could possibly lead to disclosure of some information meant to be protected by encryption. This fix improves the fix for <a href="https://access.redhat.com/security/cve/CVE-2014-0411">CVE-2014-0411</a> (<a class="bz_bug_link bz_status_CLOSED bz_closed bz_public " title="CLOSED ERRATA - CVE-2014-0411 OpenJDK: TLS/SSL handshake timing issues (JSSE, 8023069)" href="show_bug.cgi?id=1053010">bug 1053010</a>) applied via via Oracle CPU January 2014.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/icedtea | <1.13.3 | 1.13.3 |
redhat/icedtea | <2.4.7 | 2.4.7 |
Oracle JRockit | =r27.8.1 | |
Oracle JRockit | =r28.3.1 | |
Canonical Ubuntu Linux | =10.04 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =12.10 | |
Canonical Ubuntu Linux | =13.10 | |
Canonical Ubuntu Linux | =14.04 | |
Juniper Junos Space | <15.1 | |
Oracle JDK | =1.5.0-update61 | |
Oracle JDK | =1.6.0-update71 | |
Oracle JDK | =1.7.0-update51 | |
Oracle JDK | =1.8.0 | |
Oracle JRE | =1.5.0-update61 | |
Oracle JRE | =1.6.0-update71 | |
Oracle JRE | =1.7.0-update51 | |
Oracle JRE | =1.8.0 | |
Debian Debian Linux | =6.0 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
IBM Forms Viewer | >=4.0.0<4.0.0.3 | |
IBM Forms Viewer | >=8.0.0<8.0.1.1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.