First published: Fri Apr 10 2015(Updated: )
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/IcedTea6 | <1.13.7 | 1.13.7 |
redhat/IcedTea7 | <2.5.5 | 2.5.5 |
Oracle JDK 6 | =1.5.0-update8 | |
Oracle JDK 6 | =1.6.0-update91 | |
Oracle JDK 6 | =1.7.0-update76 | |
Oracle JDK 6 | =1.8.0-update40 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update81 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update91 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update76 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0469 has a serious severity level due to its potential impact on confidentiality, integrity, and availability.
To mitigate CVE-2015-0469, upgrade to a patched version of IcedTea or the Oracle Java SE that is not susceptible to this vulnerability.
CVE-2015-0469 affects Oracle Java SE versions 5.0u81, 6u91, 7u76, and 8u40.
CVE-2015-0469 is characterized as a heap-based buffer overflow issue caused by an off-by-one error.
Yes, CVE-2015-0469 can be exploited remotely by attackers through unspecified vectors.