First published: Fri Jul 17 2015(Updated: )
Oracle Java SE version 7 includes the Oracle Java Runtime Environment and<br>the Oracle Java Software Development Kit.<br>This update fixes several vulnerabilities in the Oracle Java Runtime<br>Environment and the Oracle Java Software Development Kit. Further<br>information about these flaws can be found on the Oracle Java SE Critical<br>Patch Update Advisory page, listed in the References section.<br>(CVE-2015-2590, CVE-2015-2596, CVE-2015-2601, CVE-2015-2613, CVE-2015-2619,<br>CVE-2015-2621, CVE-2015-2625, CVE-2015-2627, CVE-2015-2628, CVE-2015-2632,<br>CVE-2015-2637, CVE-2015-2638, CVE-2015-2664, CVE-2015-2808, CVE-2015-4000,<br>CVE-2015-4729, CVE-2015-4731, CVE-2015-4732, CVE-2015-4733, CVE-2015-4736,<br>CVE-2015-4748, CVE-2015-4749, CVE-2015-4760)<br>Note: With this update, Oracle JDK now disables RC4 TLS/SSL cipher suites<br>by default to address the CVE-2015-2808 issue. Refer to Red Hat Bugzilla<br>bug 1207101, linked to in the References section, for additional details<br>about this change.<br>Note: This update forces the TLS/SSL client implementation in Oracle JDK to<br>reject DH key sizes below 768 bits to address the CVE-2015-4000 issue.<br>Refer to Red Hat Bugzilla bug 1223211, linked to in the References section,<br>for additional details about this change.<br>All users of java-1.7.0-oracle are advised to upgrade to these updated<br>packages, which provide Oracle Java 7 Update 85 and resolve these issues.<br>All running instances of Oracle Java must be restarted for the update to<br>take effect.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.