First published: Wed Jul 15 2015(Updated: )
Oracle Java SE 6u101, 7u85 and 8u51 fixes an unspecified vulnerability in the 2D component (<a href="https://access.redhat.com/security/cve/CVE-2015-2638">CVE-2015-2638</a>). Upstream has CVSSv2 scored this issue as: 10.0/AV:N/AC:L/Au:N/C:C/I:C/A:C External Reference: <a href="http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA">http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA</a>
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JDK 6 | =1.6.0-update95 | |
Oracle JDK 6 | =1.7.0-update75 | |
Oracle JDK 6 | =1.7.0-update80 | |
Oracle JDK 6 | =1.8.0-update_33 | |
Oracle JDK 6 | =1.8.0-update45 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update_95 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update_75 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update_80 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update_33 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update_45 | |
Oracle JavaFX | =2.2.80 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2638 has a CVSSv2 score of 10.0, indicating it is a critical vulnerability.
CVE-2015-2638 affects Oracle Java SE versions 6u101, 7u85, and 8u51.
To fix CVE-2015-2638, update your Oracle Java SE to the latest version available.
Yes, CVE-2015-2638 can potentially allow remote code execution due to its severity.
CVE-2015-2638 specifically affects the 2D component of Oracle Java.