CVE-2015-4840: Medium severity oracle java se 7 vulnerability
It was discovered that the 2D component of OpenJDK could perform out of bounds access and possibly disclose portions of the Java Virtual Machine memory when processing specially crafted color profiles. The issue was caused by having bundled lcms2 code use fast floor() implementation. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions.
Other sources
Unspecified vulnerability in Oracle Java SE 7u85 and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality via unknown vectors related to 2D.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4840?
CVE-2015-4840 has a critical severity level due to its potential impact on confidentiality through out of bounds access.
How do I fix CVE-2015-4840?
To remediate CVE-2015-4840, upgrade to the latest version of Oracle Java SE that addresses this vulnerability.
Which versions are affected by CVE-2015-4840?
CVE-2015-4840 affects Oracle Java SE 7u85, 8u60, and Java SE Embedded 8u51.
What types of attacks can exploit CVE-2015-4840?
CVE-2015-4840 can be exploited by remote attackers to disclose sensitive information through unspecified vectors.
Is there a workaround for CVE-2015-4840?
There is no official workaround for CVE-2015-4840; the recommended action is to update to a patched version.