REDHAT-BUG-1413923: High severity openjdk vulnerability
A covert timing channel flaw was found in the ECDSA implementation in the Libraries component of OpenJDK. A remote attacker able to make a Java application generate ECDSA signatures on demand could possibly use this flaw to extract certain information about the key use via a timing side channel.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1413923?
The severity of REDHAT-BUG-1413923 is considered high due to the potential for remote attackers to extract sensitive information.
How do I fix REDHAT-BUG-1413923?
To fix REDHAT-BUG-1413923, update your OpenJDK installation to the latest patched version provided by your vendor.
What is the nature of the vulnerability in REDHAT-BUG-1413923?
The nature of the vulnerability in REDHAT-BUG-1413923 is a covert timing channel flaw in the ECDSA implementation of OpenJDK.
Who can be affected by REDHAT-BUG-1413923?
Anyone using OpenJDK for Java applications that generate ECDSA signatures can be affected by REDHAT-BUG-1413923.
Is REDHAT-BUG-1413923 exploitable remotely?
Yes, REDHAT-BUG-1413923 is potentially exploitable remotely by attackers capable of inducing ECDSA signature generation.