CVE-2014-0411

Severity

40%

Complexity

49%

Confidentiality

81%

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information about encryption keys via a timing discrepancy during the TLS/SSL handshake.

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information about encryption keys via a timing discrepancy during the TLS/SSL handshake.

CVSS 2.0 Base Score 4. CVSS Attack Vector: network. CVSS Attack Complexity: high. CVSS Vector: (AV:N/AC:H/Au:N/C:P/I:P/A:N).

Overview

Type

Oracle

First reported 11 years ago

2014-01-15 16:08:00

Last updated 7 years ago

2018-01-05 02:29:00

Affected Software

Oracle JRockit R27.7.7

r27.7.7

Oracle JRockit R28.2.9

r28.2.9

Oracle JDK 1.7.0 Update 45

1.7.0

Oracle JRE 1.7.0 Update 45

1.7.0

Oracle JDK 1.5.0 Update 55

1.5.0

Oracle JRE 1.5.0 Update 55

1.5.0

Oracle JDK 1.6.0 Update 65

1.6.0

Oracle JRE 1.6.0 Update 65

1.6.0

References

http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/d533e96c7acc

SUSE-SU-2014:0246

SUSE-SU-2014:0266

SUSE-SU-2014:0451

openSUSE-SU-2014:0174

openSUSE-SU-2014:0177

openSUSE-SU-2014:0180

SSRT101454

SSRT101455

102028

RHSA-2014:0026

RHSA-2014:0027

RHSA-2014:0030

RHSA-2014:0097

RHSA-2014:0134

RHSA-2014:0135

RHSA-2014:0136

56432

56485

56486

56487

56535

57809

59037

59071

59082

59194

59235

59251

59254

59283

59324

59339

59665

59704

59705

59872

60005

60498

60833

60835

60836

http://www.ibm.com/support/docview.wss?uid=ssg1S1004745

http://www.ibm.com/support/docview.wss?uid=swg21672078

http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html

Vendor Advisory

64758

64918

1029608

USN-2089-1

USN-2124-1

http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004656

http://www-01.ibm.com/support/docview.wss?uid=swg21669519

http://www-01.ibm.com/support/docview.wss?uid=swg21675938

http://www-01.ibm.com/support/docview.wss?uid=swg21676190

http://www-01.ibm.com/support/docview.wss?uid=swg21676373

http://www-01.ibm.com/support/docview.wss?uid=swg21676978

http://www-01.ibm.com/support/docview.wss?uid=swg21677388

http://www-01.ibm.com/support/docview.wss?uid=swg21680234

http://www-01.ibm.com/support/docview.wss?uid=swg21680387

http://www-01.ibm.com/support/docview.wss?uid=swg21682668

http://www-01.ibm.com/support/docview.wss?uid=swg21682669

http://www-01.ibm.com/support/docview.wss?uid=swg21682670

http://www-01.ibm.com/support/docview.wss?uid=swg21682671

http://www-01.ibm.com/support/docview.wss?uid=swg21682904

http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096132

RHSA-2014:0414

https://bugzilla.redhat.com/show_bug.cgi?id=1053010

oracle-cpujan2014-cve20140411(90357)

https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777

https://www.ibm.com/support/docview.wss?uid=swg21675223

https://www.ibm.com/support/docview.wss?uid=swg21677913

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.