CVE-2014-0460: Medium severity Oracle Jrockit vulnerability
It was discovered that the JNDI DNS client did not properly randomize the DNS query ID. A remote attacker could exploit this flaw to e.g. perfom DNS spoofing attacks.
Other sources
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vectors related to JNDI.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/icedteato a version that resolves this vulnerability.Fixed in 1.13.3 - Upgrade
Upgrade
redhat/icedteato a version that resolves this vulnerability.Fixed in 2.4.7
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0460?
CVE-2014-0460 is considered a moderate severity vulnerability due to its potential to enable DNS spoofing attacks.
How do I fix CVE-2014-0460?
To fix CVE-2014-0460, update the affected software to the latest versions that address this vulnerability.
What software is affected by CVE-2014-0460?
CVE-2014-0460 affects various versions of Oracle Java SE, JRockit, and several distributions of Ubuntu and Debian.
Who can exploit CVE-2014-0460?
A remote attacker can exploit CVE-2014-0460 to perform DNS spoofing attacks.
What types of attacks can be facilitated by CVE-2014-0460?
CVE-2014-0460 can facilitate DNS spoofing attacks, which can lead to unauthorized access to user data and traffic interception.