CVE-2014-0453: Medium severity Oracle Jrockit vulnerability
It was discovered that the Security component in OpenJDK could leak some timing information when preforming PKCS#1 unpadding. This could possibly lead to disclosure of some information meant to be protected by encryption.
This fix improves the fix for CVE-2014-0411 (bug 1053010) applied via via Oracle CPU January 2014.
Other sources
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/icedteato a version that resolves this vulnerability.Fixed in 1.13.3 - Upgrade
Upgrade
redhat/icedteato a version that resolves this vulnerability.Fixed in 2.4.7 - Upgrade
Upgrade
Oracle Java SE / OpenJDK Security (JSSE)to a version that resolves this vulnerability.Patch Oracle CPU January 2014
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0453?
CVE-2014-0453 has been classified as a medium severity vulnerability due to potential information disclosure.
How do I fix CVE-2014-0453?
To fix CVE-2014-0453, you should update to the latest versions of the affected software, including IcedTea 1.13.3 or 2.4.7, or ensure that your Oracle JDK and JRE versions are updated as specified.
What software is affected by CVE-2014-0453?
CVE-2014-0453 affects various versions of OpenJDK, IcedTea, Oracle JDK, Oracle JRE, and specific Ubuntu and Debian distributions.
Can CVE-2014-0453 lead to any exploits?
Yes, CVE-2014-0453 could potentially allow an attacker to exploit timing information leaks to gain access to sensitive decrypted data.
What actions should I take if I am using vulnerable software for CVE-2014-0453?
If using vulnerable software for CVE-2014-0453, immediately implement the necessary updates and monitor systems for any unusual activity.