CVE-2015-0407: Medium severity ubuntu vulnerability
Published Jan 21, 2015
·Updated
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Swing.
Affected Software
18 affected components
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=14.10
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Fedoraproject Fedora=20
redhat Enterprise Linux=5
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
Oracle JDK=1.5.0-update75
Oracle JDK=1.6.0-update85
Oracle JDK=1.7.0-update72
Oracle JDK=1.8.0-update25
Oracle JRE=1.5.0-update75
Oracle JRE=1.6.0-update85
Oracle JRE=1.7.0-update72
Oracle JRE=1.8.0-update25
Remediation
Event History
Jan 21, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0407?
CVE-2015-0407 is classified as a medium to high severity vulnerability that affects the confidentiality of Oracle Java SE.
2
How do I fix CVE-2015-0407?
To fix CVE-2015-0407, update your Oracle Java SE installations to the latest version provided by Oracle.
3
Which Oracle Java versions are affected by CVE-2015-0407?
CVE-2015-0407 affects Oracle Java SE versions 5.0u75, 6u85, 7u72, and 8u25.
4
What systems are vulnerable to CVE-2015-0407?
CVE-2015-0407 impacts systems running vulnerable versions of Oracle Java SE on various distributions including Ubuntu, Debian, and Red Hat.
5
Can CVE-2015-0407 be exploited remotely?
Yes, CVE-2015-0407 allows remote attackers to exploit the vulnerability through unknown vectors.