It was found that the RSA implementation in Java Cryptography Extension (JCE) component in OpenJDK did not follow recommended practices for implementing RSA signatures.
Acknowledgement:
This issue was discovered by Florian Weimer of Red Hat Product Security.
A flaw was found in the way the JSSE (Java Secure Socket Extension) component in OpenJDK parsed X.509 certificate options. A specially-crafted certificate could cause JSSE to raise an unexpected exception, possibly causing an application using JSSE to exit unexpectedly.