First published: Tue Oct 20 2015(Updated: )
A flaw was found in the way the Libraries component of OpenJDK handled certificate revocation lists (CRL). In certain cases, CRL checking code could fail to report that a certificate was revoked, causing the application to accept it as trusted.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JDK 6 | =1.8.0-update51 | |
Oracle JDK 6 | =1.8.0-update60 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update_51 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update_60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4868 is considered a medium severity vulnerability.
To fix CVE-2015-4868, update to the latest version of Oracle JDK or JRE that addresses this vulnerability.
CVE-2015-4868 affects Oracle JDK versions 1.8.0-update51 and 1.8.0-update60, as well as corresponding JRE versions.
CVE-2015-4868 can allow applications to accept revoked certificates as trusted, potentially leading to security breaches.
Yes, there are patches available in the later updates of Oracle JDK and JRE to mitigate the effects of CVE-2015-4868.