CVE-2014-6527
low
CVSS v3
—
CVSS v2
2.6
VIR risk
2.6
Description
Unspecified vulnerability in Oracle Java SE 7u67 and 8u20 allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2014-6476.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-6527
Vendor advisory: secalert_us@oracle.com — http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | sid | fixed | 0 |
References
- http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00021.html
- http://lists.opensuse.org/opensuse-security-announce/2014-12/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00026.html
- http://marc.info/?l=bugtraq&m=141775382904016&w=2
- http://rhn.redhat.com/errata/RHSA-2014-1657.html
- http://rhn.redhat.com/errata/RHSA-2014-1876.html
- http://rhn.redhat.com/errata/RHSA-2014-1880.html
- http://rhn.redhat.com/errata/RHSA-2014-1882.html
- http://secunia.com/advisories/61164
- http://secunia.com/advisories/61346
- http://secunia.com/advisories/61609
- http://security.gentoo.org/glsa/glsa-201502-12.xml
- http://www-01.ibm.com/support/docview.wss?uid=swg21688283
- http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
- http://www.securityfocus.com/bid/70560
- http://www.ubuntu.com/usn/USN-2388-1
- http://www.ubuntu.com/usn/USN-2388-2
- https://security-tracker.debian.org/tracker/CVE-2014-6527
Verify integrity in audit chain (admin only). AS-IS.