Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0411

Опубликовано: 15 янв. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4

Описание

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information about encryption keys via a timing discrepancy during the TLS/SSL handshake.

РелизСтатусПримечание
devel

not-affected

6b30-1.13.1-1ubuntu1
lucid

released

6b30-1.13.1-1ubuntu2~0.10.04.1
precise

released

6b30-1.13.1-1ubuntu2~0.12.04.1
quantal

released

6b30-1.13.1-1ubuntu2~0.12.10.1
raring

ignored

end of life, was deferred
saucy

released

6b30-1.13.1-1ubuntu2~0.13.10.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

7u51-2.4.4-1ubuntu1
lucid

DNE

precise

released

7u51-2.4.4-0ubuntu0.12.04.2
quantal

released

7u51-2.4.4-0ubuntu0.12.10.2
raring

released

7u51-2.4.4-0ubuntu0.13.04.2
saucy

released

7u51-2.4.4-0ubuntu0.13.10.1
upstream

released

7u51-2.4.4-1

Показывать по

EPSS

Процентиль: 81%
0.01675
Низкий

4 Medium

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information about encryption keys via a timing discrepancy during the TLS/SSL handshake.

nvd
больше 11 лет назад

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information about encryption keys via a timing discrepancy during the TLS/SSL handshake.

debian
больше 11 лет назад

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JR ...

github
около 3 лет назад

Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information about encryption keys via a timing discrepancy during the TLS/SSL handshake.

fstec
больше 11 лет назад

Уязвимость средства разработки приложений Java Development Kit, позволяющая удаленному злоумышленнику нарушить конфиденциальность и целостность данных

EPSS

Процентиль: 81%
0.01675
Низкий

4 Medium

CVSS2