First published: Mon Jul 13 2015(Updated: )
It was discovered that ICU Layout Engine was missing multiple boundary checks. These could lead to buffer overflows and JVM memory corruption. A specially crafted file could cause an application using ICU to parse untrusted font files to crash and, possibly, execute arbitrary code. ICU code is embedded the 2D component in OpenJDK and used by FontManager. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JDK | =1.6.0-update95 | |
Oracle JDK | =1.7.0-update80 | |
Oracle JDK | =1.8.0-update45 | |
Oracle JRE | =1.6.0-update_95 | |
Oracle JRE | =1.7.0-update_80 | |
Oracle JRE | =1.8.0-update_45 | |
debian/icu | 67.1-7 72.1-3 72.1-5 | |
debian/openjdk-8 | 8u432-b06-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4760 is an unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45 that allows remote attackers to affect confidentiality, integrity, and availability.
Oracle JDK 1.6.0-update95, 1.7.0-update80, 1.8.0-update45, Oracle JRE 1.6.0-update_95, 1.7.0-update_80, and 1.8.0-update_45 are affected.
CVE-2015-4760 has a severity rating of critical.
You can find more information about CVE-2015-4760 at the following references: [link1](http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html#AppendixJAVA), [link2](https://rhn.redhat.com/errata/RHSA-2015-1230.html), [link3](https://rhn.redhat.com/errata/RHSA-2015-1229.html).
The CWE for CVE-2015-4760 is CWE-119.