CVE-2015-2613: Medium severity oracle java se 7 vulnerability
It was discovered that the Elliptic Curve (EC) cryptography code as used in Mozilla NSS (Network Security Services) library and OpenJDK JCE (Java Cryptography Extension) component failed to properly validate EC parameters as used in ECDHDerive() function, which performs ECDH (Elliptic Curve Diffie-Hellman) key derivation. A remote attacker could use this flaw to disclose sensitive information.
The OpenJDK packages as shipped with Red Hat Enterprise Linux 5, 6 and 7 do not build the affected EC code and are therefore not directly affected. Future versions may provide EC support via NSS, see e.g. bug 1075702.
Other sources
Unspecified vulnerability in Oracle Java SE 7u80 and 8u45, and Java SE ...
— Debian
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2015-2613.
What software versions are affected?
Oracle Java SE 7u80 and 8u45, and Java SE Embedded 7u75 and 8u33 are affected.
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability to affect confidentiality via vectors related to JCE.
What is the severity level of CVE-2015-2613?
The severity level of CVE-2015-2613 is medium.
Are there any recommended fixes for this vulnerability?
Yes, there are recommended fixes available for this vulnerability. Please refer to the provided references for more information.