CVE-2014-2401: Medium severity Oracle JavaFX vulnerability
Oracle Java SE 5.0u75, 6u75, 7u55 and 8u5 fixes an unspecified vulnerability in the 2D component (CVE-2014-2401). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Other sources
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality via unknown vectors related to 2D.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-oracle-1:1.7.0.55-1jpp.2.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-sun-1:1.6.0.75-1jpp.3.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-oracle-1:1.7.0.55-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-sun-1:1.6.0.75-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-ibm-1:1.7.0.7.0-1jpp.1.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.5.0-ibm-1:1.5.0.16.6-1jpp.1.el5_10 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.0-ibm-1:1.7.0.7.0-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.6.0-ibm-1:1.6.0.16.0-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.5.0-ibm-1:1.5.0.16.6-1jpp.1.el6_5 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 1.7.1-ibm-1:1.7.1.1.0-1jpp.2.el7_0 - Upgrade
Upgrade
Oracle Java SE 5.0to a version that resolves this vulnerability.Fixed in 5.0u75 - Upgrade
Upgrade
Oracle Java SE 6to a version that resolves this vulnerability.Fixed in 6u75 - Upgrade
Upgrade
Oracle Java SE 7to a version that resolves this vulnerability.Fixed in 7u55 - Upgrade
Upgrade
Oracle Java SE 8to a version that resolves this vulnerability.Fixed in 8u5
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2014-2401?
CVE-2014-2401 is rated with a CVSSv2 score of 5.0, indicating medium severity.
How do I fix CVE-2014-2401?
To address CVE-2014-2401, update your Oracle Java SE installation to a patched version as specified by your vendor.
Which Java versions are affected by CVE-2014-2401?
CVE-2014-2401 impacts Oracle Java SE versions 5.0u75, 6u75, 7u55, and 8u5.
Is CVE-2014-2401 exploitable remotely?
Yes, CVE-2014-2401 has remote exploit potential as defined in its CVSSv2 scoring.
What components of Java are impacted by CVE-2014-2401?
CVE-2014-2401 specifically affects the 2D component of Java.