First published: Tue Jul 15 2014(Updated: )
It was discovered that Java_sun_management_GcInfoBuilder_getLastGcInfo0() may return unexpected values. An untrusted Java application or applet could possibly use this flaw to impact the integrity of the Java Virtual Machine.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JDK 6 | =1.7.0-update60 | |
Oracle JDK 6 | =1.8.0-update5 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update60 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4266 is considered a critical vulnerability affecting the integrity of the Java Virtual Machine.
To fix CVE-2014-4266, upgrade your Oracle JDK or JRE to versions 1.7.0-update61 or 1.8.0-update6 or newer.
CVE-2014-4266 affects Oracle Java SE 7u60 and 8u5.
Yes, an untrusted Java application or applet can exploit CVE-2014-4266, impacting the integrity of the JVM.
The consequences of CVE-2014-4266 could include compromised integrity of the Java Virtual Machine, leading to security vulnerabilities.