First published: Tue Oct 20 2015(Updated: )
A flaw was found in the way the Libraries component of OpenJDK handled certificate revocation lists (CRL). In certain cases, CRL checking code could fail to report that a certificate was revoked, causing the application to accept it as trusted.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JDK | =1.8.0-update51 | |
Oracle JDK | =1.8.0-update60 | |
Oracle JRE | =1.8.0-update_51 | |
Oracle JRE | =1.8.0-update_60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.