First published: Mon Apr 14 2014(Updated: )
It was discovered that ICC profiles were not parsed correctly. An untrusted Java application or applet could possibly use this flaw to cause a denial of service.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/icedtea | <2.4.7 | 2.4.7 |
Ubuntu | =10.04 | |
Ubuntu | =12.04 | |
Ubuntu | =12.10 | |
Ubuntu | =13.10 | |
Ubuntu | =14.04 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update51 | |
Oracle OpenJDK 1.8.0 | =1.8.0 | |
Oracle JRE | =1.7.0-update51 | |
Oracle JRE | =1.8.0 | |
Debian | =6.0 | |
Debian | =7.0 | |
Debian | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0459 is classified as a denial of service vulnerability.
To mitigate CVE-2014-0459, update to a version of Oracle Java SE that is above 1.7.0-update51 or 1.8.0.
CVE-2014-0459 affects Oracle Java SE 7u51, Oracle Java SE 8, and various versions of Debian and Ubuntu Linux.
Yes, CVE-2014-0459 can be exploited remotely by untrusted Java applications or applets.
CVE-2014-0459 enables a denial of service attack due to the incorrect parsing of ICC profiles.