CVE-2014-0454: High severity Ubuntu vulnerability
It was discovered that the AlgorithmChecker and SignatureAndHashAlgorithm classes did not properly prevent the SIGNATUREPRIMITIVESET set from being modified. An untrusted Java application or applet could possibly use this flaw to alter the content of the SIGNATUREPRIMITIVESET set.
Other sources
Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/icedteato a version that resolves this vulnerability.Fixed in 2.4.7
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0454?
CVE-2014-0454 is classified as a critical vulnerability due to its potential impact on the integrity of cryptographic processes.
How do I fix CVE-2014-0454?
To remediate CVE-2014-0454, upgrade to the affected software versions specified in the security advisories, such as IcedTea 2.4.7 or Oracle JDK 1.7.0-update51.
What software is affected by CVE-2014-0454?
CVE-2014-0454 affects various versions of IcedTea, Oracle JDK, Oracle JRE, and IBM Forms Viewer on specific operating systems.
Can CVE-2014-0454 affect my Java applications?
Yes, if your applications use the vulnerable versions of the JDK or JRE, they may be at risk of exploitation due to this vulnerability.
Is my operating system affected by CVE-2014-0454?
CVE-2014-0454 can affect operating systems running vulnerable versions of Java, such as Ubuntu 12.10, 13.10, and 14.04.