CVE-2014-0411
published 2014-01-15CVE-2014-0411: Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers…
PriorityP425medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
2.41%
82.3th percentile
Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information about encryption keys via a timing discrepancy during the TLS/SSL handshake.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jrockit | — | — |
| oracle | jrockit | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
vendor_ubuntu7.5HIGH
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nginx: SMTP STARTTLS plaintext injection flaw
vendor_redhat·2014-08-05·CVSS 6.8
CVE-2014-3556 [MEDIUM] nginx: SMTP STARTTLS plaintext injection flaw
nginx: SMTP STARTTLS plaintext injection flaw
The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
Statement: This issue did not affect the versions of nginx as shipped with Red Hat Software Collections 1 for Red Hat Enterprise Linux 6 and 7.
Package: nginx14-nginx (Red Hat Software Collections) - Not affected
Package: nginx16-nginx (Red Hat Software Collections) - Affected
Ubuntu
OpenJDK 6 regression
vendor_ubuntu·2014-04-08·CVSS 7.5
[HIGH] OpenJDK 6 regression
Title: OpenJDK 6 regression
Summary: USN-2124-1 introduced a regression in OpenJDK 6.
USN-2124-1 fixed vulnerabilities in OpenJDK 6. Due to an upstream
regression, memory was not properly zeroed under certain circumstances
which could lead to instability. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
A vulnerability was discovered in the OpenJDK JRE related to information
disclosure and data integrity. An attacker could exploit this to expose
sensitive data over the network. (CVE-2014-0411)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2013-5878, CVE
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2014-02-27·CVSS 7.5
CVE-2013-5878 [HIGH] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
A vulnerability was discovered in the OpenJDK JRE related to information
disclosure and data integrity. An attacker could exploit this to expose
sensitive data over the network. (CVE-2014-0411)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2013-5878, CVE-2013-5907, CVE-2014-0373, CVE-2014-0422,
CVE-2014-0428)
Two vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An attacker could exploit these to expose sensitive
data over the network. (CVE-2013-5884, CVE-2014-0368)
Two vul
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2014-01-23·CVSS 6.4
CVE-2013-5817 [MEDIUM] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,
CVE-2013-5804, CVE-2014-0411)
Several vulnerabilities were discovered in the OpenJDK JRE related to
availability. An attacker could exploit these to cause a denial of service.
(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,
CVE-2013-5910)
Several vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,
CVE-2013-5820, CVE-2014-0376, CVE-2014-0416)
Several vulnerabilities we
Red Hat
OpenJDK: TLS/SSL handshake timing issues (JSSE, 8023069)
vendor_redhat·2014-01-14·CVSS 4.0
CVE-2014-0411 [MEDIUM] OpenJDK: TLS/SSL handshake timing issues (JSSE, 8023069)
OpenJDK: TLS/SSL handshake timing issues (JSSE, 8023069)
Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information about encryption keys via a timing discrepancy during the TLS/SSL handshake.
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 7) - Not affected
Package: java-1.7.0-openjdk (Red Hat Enterprise Linux 7) - Not affected
Package: java-1.7.0-oracle (Red Hat Enterprise Linux 7) - Not affected
GHSA
GHSA-mqjj-vv82-vh6r: Unspecified vulnerability in Oracle Java SE 5
ghsa_unreviewed·2022-05-13
CVE-2014-0411 [MEDIUM] GHSA-mqjj-vv82-vh6r: Unspecified vulnerability in Oracle Java SE 5
Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to obtain sensitive information about encryption keys via a timing discrepancy during the TLS/SSL handshake.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0453 OpenJDK: RSA unpadding timing issues (Security, 8027766)
bugzilla·2014-04-11·CVSS 4.0
CVE-2014-0453 [MEDIUM] CVE-2014-0453 OpenJDK: RSA unpadding timing issues (Security, 8027766)
CVE-2014-0453 OpenJDK: RSA unpadding timing issues (Security, 8027766)
It was discovered that the Security component in OpenJDK could leak some timing information when preforming PKCS#1 unpadding. This could possibly lead to disclosure of some information meant to be protected by encryption.
This fix improves the fix for CVE-2014-0411 (bug 1053010) applied via via Oracle CPU January 2014.
Discussion:
Fixed now in Oracle Java SE 5.0u75, 6u75, 7u55 and 8u5 via Oracle Critical Patch Update Advisory - April 2014.
Fixed in IcedTea6 1.13.3 and IcedTea7 2.4.7:
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2014-April/027214.html
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2014-April/027222.html
External References:
http://www.oracle.com/technetwork/topics/security/cpuapr2
Bugzilla
CVE-2014-0411 OpenJDK: TLS/SSL handshake timing issues (JSSE, 8023069)
bugzilla·2014-01-14·CVSS 4.0
CVE-2014-0411 [MEDIUM] CVE-2014-0411 OpenJDK: TLS/SSL handshake timing issues (JSSE, 8023069)
CVE-2014-0411 OpenJDK: TLS/SSL handshake timing issues (JSSE, 8023069)
It was discovered that the JSSE component in OpenJDK could leak some timing information during the TLS/SSL handshake. This could possibly lead to disclosure of some information about negotiated encryption keys.
Discussion:
Public now via Oracle CPU January 2014. Fixed in Oracle JDK 7u51, 6u71 and 5.0u61.
External References:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2014:0027 https://rhn.redhat.com/errata/RHSA-2014-0027.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2014:0026 https://rhn.redhat.com/errata/RHSA-2014-0026.html
---
Thi
http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/d533e96c7acchttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00024.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00105.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00107.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00000.htmlhttp://marc.info/?l=bugtraq&m=139402697611681&w=2http://marc.info/?l=bugtraq&m=139402749111889&w=2http://osvdb.org/102028http://rhn.redhat.com/errata/RHSA-2014-0026.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0027.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0030.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0097.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0134.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0135.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0136.htmlhttp://secunia.com/advisories/56432http://secunia.com/advisories/56485http://secunia.com/advisories/56486http://secunia.com/advisories/56487http://secunia.com/advisories/56535http://secunia.com/advisories/57809http://secunia.com/advisories/59037http://secunia.com/advisories/59071http://secunia.com/advisories/59082http://secunia.com/advisories/59194http://secunia.com/advisories/59235http://secunia.com/advisories/59251http://secunia.com/advisories/59254http://secunia.com/advisories/59283http://secunia.com/advisories/59324http://secunia.com/advisories/59339http://secunia.com/advisories/59665http://secunia.com/advisories/59704http://secunia.com/advisories/59705http://secunia.com/advisories/59872http://secunia.com/advisories/60005http://secunia.com/advisories/60498http://secunia.com/advisories/60833http://secunia.com/advisories/60835http://secunia.com/advisories/60836http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004656http://www-01.ibm.com/support/docview.wss?uid=swg21669519http://www-01.ibm.com/support/docview.wss?uid=swg21675938http://www-01.ibm.com/support/docview.wss?uid=swg21676190http://www-01.ibm.com/support/docview.wss?uid=swg21676373http://www-01.ibm.com/support/docview.wss?uid=swg21676978http://www-01.ibm.com/support/docview.wss?uid=swg21677388http://www-01.ibm.com/support/docview.wss?uid=swg21680234http://www-01.ibm.com/support/docview.wss?uid=swg21680387http://www-01.ibm.com/support/docview.wss?uid=swg21682668http://www-01.ibm.com/support/docview.wss?uid=swg21682669http://www-01.ibm.com/support/docview.wss?uid=swg21682670http://www-01.ibm.com/support/docview.wss?uid=swg21682671http://www-01.ibm.com/support/docview.wss?uid=swg21682904http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096132http://www.ibm.com/support/docview.wss?uid=ssg1S1004745http://www.ibm.com/support/docview.wss?uid=swg21672078http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlhttp://www.securityfocus.com/bid/64758http://www.securityfocus.com/bid/64918http://www.securitytracker.com/id/1029608http://www.ubuntu.com/usn/USN-2089-1http://www.ubuntu.com/usn/USN-2124-1https://access.redhat.com/errata/RHSA-2014:0414https://bugzilla.redhat.com/show_bug.cgi?id=1053010https://exchange.xforce.ibmcloud.com/vulnerabilities/90357https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04166777https://www.ibm.com/support/docview.wss?uid=swg21675223https://www.ibm.com/support/docview.wss?uid=swg21677913http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/d533e96c7acchttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00024.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00105.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00107.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00000.htmlhttp://marc.info/?l=bugtraq&m=139402697611681&w=2http://marc.info/?l=bugtraq&m=139402749111889&w=2http://osvdb.org/102028http://rhn.redhat.com/errata/RHSA-2014-0026.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0027.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0030.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0097.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0134.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0135.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0136.htmlhttp://secunia.com/advisories/56432http://secunia.com/advisories/56485http://secunia.com/advisories/56486http://secunia.com/advisories/56487http://secunia.com/advisories/56535http://secunia.com/advisories/57809http://secunia.com/advisories/59037http://secunia.com/advisories/59071http://secunia.com/advisories/59082http://secunia.com/advisories/59194http://secunia.com/advisories/59235http://secunia.com/advisories/59251
+ 42 more references
2014-01-15
Published