CVE-2015-2659: Medium severity oracle java se 7 vulnerability
It was discovered that GCM (Galois Counter Mode), a mode of operation for symmetric key cryptographic block ciphers, implementation in the Security component of OpenJDK failed to properly perform null check. This could cause crash when application performed encryption using a block cipher in GCM mode.
GCM mode is used in several cipher suites defined for TLS 1.2. Affected code was added to OpenJDK version 8, earlier versions 6 and 7 do not contain it and are therefore unaffected.
Other sources
Unspecified vulnerability in Oracle Java SE 8u45 and Java SE Embedded 8u33 allows remote attackers to affect availability via unknown vectors related to Security.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2659?
CVE-2015-2659 is classified as a medium severity vulnerability due to its potential to cause application crashes.
How do I fix CVE-2015-2659?
To mitigate CVE-2015-2659, update your Oracle JDK or JRE to versions 1.8.0-update_44 or later.
What software is affected by CVE-2015-2659?
CVE-2015-2659 affects specific versions of Oracle JDK and JRE including 1.8.0-update_33 and 1.8.0-update_45.
What impact does CVE-2015-2659 have on applications?
CVE-2015-2659 can lead to application crashes during encryption operations using the Galois Counter Mode.
Is CVE-2015-2659 an orchestrated attack vulnerability?
CVE-2015-2659 is not specifically an orchestrated attack vulnerability but it can lead to service disruptions if exploited.