First published: Mon Apr 14 2014(Updated: )
It was discovered that the ServiceLoader did not perform exception handling in a secure manner. An untrusted Java application or applet could possibly use this flaw to bypass security mechanisms and perform operations with full permissions.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/icedtea | <1.13.3 | 1.13.3 |
redhat/icedtea | <2.4.7 | 2.4.7 |
BEA JRockit | =r27.8.1 | |
BEA JRockit | =r28.3.1 | |
Ubuntu Linux | =10.04 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =12.10 | |
Ubuntu Linux | =13.10 | |
Ubuntu Linux | =14.04 | |
Juniper Networks Junos Space | <15.1 | |
Oracle JDK 6 | =1.5.0-update61 | |
Oracle JDK 6 | =1.6.0-update71 | |
Oracle JDK 6 | =1.7.0-update51 | |
Oracle JDK 6 | =1.8.0 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update61 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update71 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update51 | |
Oracle Java Runtime Environment (JRE) | =1.8.0 | |
Debian GNU/Linux | =6.0 | |
Debian GNU/Linux | =7.0 | |
Debian GNU/Linux | =8.0 | |
IBM Forms Viewer | >=4.0.0<4.0.0.3 | |
IBM Forms Viewer | >=8.0.0<8.0.1.1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0457 is considered a critical vulnerability due to its potential to allow untrusted Java applications to bypass security mechanisms.
To mitigate CVE-2014-0457, update to the recommended versions of the affected software, such as IcedTea 1.13.3 or later, and Oracle JDK versions that include the fix.
CVE-2014-0457 affects multiple versions of Oracle JDK, JRE, and IcedTea, as well as specific versions of Ubuntu and Debian Linux.
Yes, CVE-2014-0457 can be exploited remotely if an untrusted Java application is executed, potentially allowing an attacker to gain full permissions.
Failing to address CVE-2014-0457 may lead to unauthorized access and control over affected systems, posing significant security risks.