USN-2706-1: OpenJDK 6 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to information disclosure, data integrity, and availability. An attacker could exploit these to cause a denial of service or expose sensitive data over the network. (CVE-2015-2590, CVE-2015-2628, CVE-2015-4731, CVE-2015-4732, CVE-2015-4733, CVE-2015-4760, CVE-2015-4748) Several vulnerabilities were discovered in the cryptographic components of the OpenJDK JRE. An attacker could exploit these to expose sensitive data over the network. (CVE-2015-2601, CVE-2015-2808, CVE-2015-4000, CVE-2015-2625, CVE-2015-2613) As a security improvement, this update modifies OpenJDK behavior to disable RC4 TLS/SSL cipher suites by default. As a security improvement, this update modifies OpenJDK behavior to reject DH key sizes below 768 bits by default, preventing a possible downgrade attack. Several vulnerabilities were discovered in the OpenJDK JRE related to information disclosure. An attacker could exploit these to expose sensitive data over the network. (CVE-2015-2621, CVE-2015-2632) A vulnerability was discovered with how the JNDI component of the OpenJDK JRE handles DNS resolutions. A remote attacker could exploit this to cause a denial of service. (CVE-2015-4749)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is USN-2706-1.
What is the severity of USN-2706-1?
The severity of USN-2706-1 is not specified in the provided information.
Which software versions are affected by USN-2706-1?
The software versions affected by USN-2706-1 are OpenJDK 6 with versions up to exclusive 6b36-1.13.8-0ubuntu1~12.04.
What are the potential impacts of USN-2706-1?
The potential impacts of USN-2706-1 include denial of service attacks and exposure of sensitive data over the network.
Where can I find more information about USN-2706-1?
You can find more information about USN-2706-1 at the following references: [link1](https://ubuntu.com/security/CVE-2015-2590), [link2](https://ubuntu.com/security/CVE-2015-2601), [link3](https://ubuntu.com/security/CVE-2015-2621).