CVE-2014-6591
low
CVSS v3
—
CVSS v2
2.6
VIR risk
2.6
Description
Unspecified vulnerability in the Java SE component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6585.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-6591
Vendor advisory: secalert_us@oracle.com — http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 52.1-7 |
| debian | bullseye | fixed | 52.1-7 |
| debian | forky | fixed | 52.1-7 |
| debian | sid | fixed | 52.1-7 |
| debian | trixie | fixed | 52.1-7 |
References
- http://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04583581
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00018.html
- http://marc.info/?l=bugtraq&m=142496355704097&w=2
- http://marc.info/?l=bugtraq&m=142607790919348&w=2
- http://rhn.redhat.com/errata/RHSA-2015-0068.html
- http://rhn.redhat.com/errata/RHSA-2015-0079.html
- http://rhn.redhat.com/errata/RHSA-2015-0080.html
- http://rhn.redhat.com/errata/RHSA-2015-0085.html
- http://rhn.redhat.com/errata/RHSA-2015-0086.html
- http://rhn.redhat.com/errata/RHSA-2015-0136.html
- http://rhn.redhat.com/errata/RHSA-2015-0264.html
- http://www.debian.org/security/2015/dsa-3144
- http://www.debian.org/security/2015/dsa-3147
- http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.securityfocus.com/bid/72175
- http://www.securitytracker.com/id/1031580
- http://www.ubuntu.com/usn/USN-2486-1
- http://www.ubuntu.com/usn/USN-2487-1
- http://www.vmware.com/security/advisories/VMSA-2015-0003.html
- https://security.gentoo.org/glsa/201507-14
- https://security.gentoo.org/glsa/201603-14
- https://www-304.ibm.com/support/docview.wss?uid=swg21695474
Verify integrity in audit chain (admin only). AS-IS.