CVE-2014-6591
published 2015-01-21CVE-2014-6591: Unspecified vulnerability in the Java SE component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown…
low2.6CVSS 3.1
AVNACHAuNCPINAN
Unspecified vulnerability in the Java SE component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6585.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | icu | < icu 52.1-7 (bookworm) | icu 52.1-7 (bookworm) |
| debian | icu | < icu 52.1-7.1 (bookworm) | icu 52.1-7.1 (bookworm) |
| debian | openjdk-8 | < icu 52.1-7 (bookworm) | icu 52.1-7 (bookworm) |
| debian | openjdk-8 | < icu 52.1-7.1 (bookworm) | icu 52.1-7.1 (bookworm) |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
CVSS provenance
nvd2.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv10.0CRITICAL
GHSA
GHSA-mr97-jqw9-fp77: Unspecified vulnerability in Oracle Java SE 5
ghsa_unreviewed·2022-05-13·CVSS 2.6
CVE-2014-6585 [LOW] GHSA-mr97-jqw9-fp77: Unspecified vulnerability in Oracle Java SE 5
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6591.
GHSA
GHSA-7hw8-8c2x-83rg: Unspecified vulnerability in the Java SE component in Oracle Java SE 5
ghsa_unreviewed·2022-05-13·CVSS 2.6
CVE-2014-6591 [LOW] GHSA-7hw8-8c2x-83rg: Unspecified vulnerability in the Java SE component in Oracle Java SE 5
Unspecified vulnerability in the Java SE component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6585.
OSV
icu vulnerabilities
osv·2015-03-05·CVSS 10.0
CVE-2013-1569 [CRITICAL] icu vulnerabilities
icu vulnerabilities
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. This issue only affected
Ubuntu 12.04 LTS. (CVE-2013-1569, CVE-2013-2383, CVE-2013-2384,
CVE-2013-2419)
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. (CVE-2014-6585,
CVE-2014-6591)
It was discovered that ICU incorrectly handled memory operations when
processing regular expressions. If a
OSV
openjdk-7 vulnerabilities
osv·2015-01-28·CVSS 3.4
CVE-2014-3566 [LOW] openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-3566, CVE-2014-6587, CVE-2014-6601, CVE-2015-0395,
CVE-2015-0408, CVE-2015-0412)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An attacker could exploit these to expose sensitive
data over the network. (CVE-2014-6585, CVE-2014-6591, CVE-2015-0400,
CVE-2015-0407)
A vulnerability was discovered in the OpenJDK JRE related to
information disclosure and integrity. An attacker could exploit this to
expose sensitive data over the network. (CVE-2014-6593)
A vulnerability was discovere
OSV
CVE-2014-6591: Unspecified vulnerability in the Java SE component in Oracle Java SE 5
osv·2015-01-21·CVSS 2.6
CVE-2014-6591 [LOW] CVE-2014-6591: Unspecified vulnerability in the Java SE component in Oracle Java SE 5
Unspecified vulnerability in the Java SE component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6585.
OSV
CVE-2014-6585: Unspecified vulnerability in Oracle Java SE 5
osv·2015-01-21·CVSS 2.6
CVE-2014-6585 [LOW] CVE-2014-6585: Unspecified vulnerability in Oracle Java SE 5
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6591.
Ubuntu
ICU vulnerabilities
vendor_ubuntu·2015-03-10·CVSS 10.0
CVE-2013-1569 [CRITICAL] ICU vulnerabilities
Title: ICU vulnerabilities
Summary: ICU could be made to crash or run programs as your login if it processed
specially crafted data.
USN-2522-1 fixed vulnerabilities in ICU. On Ubuntu 12.04 LTS, the font
patches caused a regression when using LibreOffice Calc. The patches have
now been updated to fix the regression.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. This issue only affected
Ubuntu 12.04 LTS. (CVE-2013-1569, CVE-2013-2383, CVE-2013-2384,
CVE-2013-2419)
It was discovered that ICU incorrectly ha
Ubuntu
ICU regression
vendor_ubuntu·2015-03-06·CVSS 10.0
[CRITICAL] ICU regression
Title: ICU regression
Summary: USN-2522-1 introduced a regression in ICU.
USN-2522-1 fixed vulnerabilities in ICU. On Ubuntu 12.04 LTS, the font
patches caused a regression when using LibreOffice Calc. The patches have
been temporarily backed out until the regression is investigated.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. This issue only affected
Ubuntu 12.04 LTS. (CVE-2013-1569, CVE-2013-2383, CVE-2013-2384,
CVE-2013-2419)
It was discovered that ICU incorrectly handled memory operations when
proc
Ubuntu
ICU vulnerabilities
vendor_ubuntu·2015-03-05·CVSS 10.0
CVE-2013-1569 [CRITICAL] ICU vulnerabilities
Title: ICU vulnerabilities
Summary: ICU could be made to crash or run programs as your login if it processed
specially crafted data.
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. This issue only affected
Ubuntu 12.04 LTS. (CVE-2013-1569, CVE-2013-2383, CVE-2013-2384,
CVE-2013-2419)
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. (CVE-2014-6585,
CVE-2014
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2015-01-28·CVSS 3.4
CVE-2014-3566 [LOW] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-3566, CVE-2014-6587, CVE-2014-6601, CVE-2015-0395,
CVE-2015-0408, CVE-2015-0412)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An attacker could exploit these to expose sensitive
data over the network. (CVE-2014-6585, CVE-2014-6591, CVE-2015-0400,
CVE-2015-0407)
A vulnerability was discovered in the OpenJDK JRE related to
information disclosure and integrity. An attacker could exploit this to
expose sensitive dat
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2015-01-27·CVSS 3.4
CVE-2014-3566 [LOW] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-3566, CVE-2014-6587, CVE-2014-6601, CVE-2015-0395,
CVE-2015-0408, CVE-2015-0412)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An attacker could exploit these to expose sensitive
data over the network. (CVE-2014-6585, CVE-2014-6591, CVE-2015-0400,
CVE-2015-0407)
A vulnerability was discovered in the OpenJDK JRE related to
information disclosure and integrity. An attacker could exploit this to
expose sensitive dat
Red Hat
ICU: font parsing OOB read (OpenJDK 2D, 8056276)
vendor_redhat·2015-01-20·CVSS 2.6
CVE-2014-6591 [LOW] CWE-125 ICU: font parsing OOB read (OpenJDK 2D, 8056276)
ICU: font parsing OOB read (OpenJDK 2D, 8056276)
Unspecified vulnerability in the Java SE component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6585.
A boundary check flaw was found in the font parsing code in the 2D component in OpenJDK. A specially crafted font file could allow an untrusted Java application or applet to disclose portions of the Java Virtual Machine memory.
Package: icu (Red Hat Enterprise Linux 5) - Will not fix
Package: icu (Red Hat Enterprise Linux 6) - Will not fix
Package: icu (Red Hat Enterprise Linux 7) - Will not fix
Package: java-1.8.0-openjdk (Red Hat Enterprise Linux 7) - Not affected
Package: java-1.8.0-oracle (Red Hat Enterpri
Red Hat
ICU: font parsing OOB read (OpenJDK 2D, 8055489)
vendor_redhat·2015-01-20·CVSS 2.6
CVE-2014-6585 [LOW] CWE-125 ICU: font parsing OOB read (OpenJDK 2D, 8055489)
ICU: font parsing OOB read (OpenJDK 2D, 8055489)
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6591.
A boundary check flaw was found in the font parsing code in the 2D component in OpenJDK. A specially crafted font file could allow an untrusted Java application or applet to disclose portions of the Java Virtual Machine memory.
Package: icu (Red Hat Enterprise Linux 5) - Will not fix
Package: icu (Red Hat Enterprise Linux 6) - Will not fix
Package: icu (Red Hat Enterprise Linux 7) - Will not fix
Package: java-1.8.0-openjdk (Red Hat Enterprise Linux 7) - Not affected
Package: java-1.8.0-oracle (Red Hat Enterprise Linux 7) - Not affecte
Debian
CVE-2014-6591: icu - Unspecified vulnerability in the Java SE component in Oracle Java SE 5.0u75, 6u8...
vendor_debian·2014·CVSS 2.6
CVE-2014-6591 [LOW] CVE-2014-6591: icu - Unspecified vulnerability in the Java SE component in Oracle Java SE 5.0u75, 6u8...
Unspecified vulnerability in the Java SE component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6585.
Scope: local
bookworm: resolved (fixed in 52.1-7)
bullseye: resolved (fixed in 52.1-7)
forky: resolved (fixed in 52.1-7)
sid: resolved (fixed in 52.1-7)
trixie: resolved (fixed in 52.1-7)
Debian
CVE-2014-6585: icu - Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows ...
vendor_debian·2014·CVSS 2.6
CVE-2014-6585 [LOW] CVE-2014-6585: icu - Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows ...
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6591.
Scope: local
bookworm: resolved (fixed in 52.1-7.1)
bullseye: resolved (fixed in 52.1-7.1)
forky: resolved (fixed in 52.1-7.1)
sid: resolved (fixed in 52.1-7.1)
trixie: resolved (fixed in 52.1-7.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-6591 CVE-2014-6585 mingw-icu: various flaws [fedora-all]
bugzilla·2015-01-22·CVSS 2.6
CVE-2014-6591 [LOW] CVE-2014-6591 CVE-2014-6585 mingw-icu: various flaws [fedora-all]
CVE-2014-6591 CVE-2014-6585 mingw-icu: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whil
Bugzilla
CVE-2014-6591 CVE-2014-6585 mingw-icu: various flaws [epel-7]
bugzilla·2015-01-22·CVSS 2.6
CVE-2014-6591 [LOW] CVE-2014-6591 CVE-2014-6585 mingw-icu: various flaws [epel-7]
CVE-2014-6591 CVE-2014-6585 mingw-icu: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for mingw-icu: see blocks bug list for full det
Bugzilla
CVE-2014-6591 CVE-2014-6585 icu: various flaws [fedora-all]
bugzilla·2015-01-22·CVSS 2.6
CVE-2014-6591 [LOW] CVE-2014-6591 CVE-2014-6585 icu: various flaws [fedora-all]
CVE-2014-6591 CVE-2014-6585 icu: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
Bugzilla
CVE-2014-6591 ICU: font parsing OOB read (OpenJDK 2D, 8056276)
bugzilla·2015-01-19·CVSS 2.6
CVE-2014-6591 [LOW] CVE-2014-6591 ICU: font parsing OOB read (OpenJDK 2D, 8056276)
CVE-2014-6591 ICU: font parsing OOB read (OpenJDK 2D, 8056276)
A flaw was found in the way the layout component of ICU parsed font files. A specially crafted file could cause an application using ICU to parse untrusted font files to perform an invalid memory access and possibly disclose portion of its memory.
ICU code is embedded the 2D component in OpenJDK and used by FontManager. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions.
Discussion:
Created attachment 981490
OpenJDK-8 patch
---
Public now via Oracle Critical Patch Update - January 2015. Fixed in Oracle Java SE 5.0u81, 6u91, 7u75, and 8u31.
External References:
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html#AppendixJAVA
---
This issue has b
http://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04583581http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00018.htmlhttp://marc.info/?l=bugtraq&m=142496355704097&w=2http://marc.info/?l=bugtraq&m=142607790919348&w=2http://rhn.redhat.com/errata/RHSA-2015-0068.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0079.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0080.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0085.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0086.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0136.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0264.htmlhttp://www.debian.org/security/2015/dsa-3144http://www.debian.org/security/2015/dsa-3147http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.securityfocus.com/bid/72175http://www.securitytracker.com/id/1031580http://www.ubuntu.com/usn/USN-2486-1http://www.ubuntu.com/usn/USN-2487-1http://www.vmware.com/security/advisories/VMSA-2015-0003.htmlhttps://security.gentoo.org/glsa/201507-14https://security.gentoo.org/glsa/201603-14https://www-304.ibm.com/support/docview.wss?uid=swg21695474http://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04583581http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00018.htmlhttp://marc.info/?l=bugtraq&m=142496355704097&w=2http://marc.info/?l=bugtraq&m=142607790919348&w=2http://rhn.redhat.com/errata/RHSA-2015-0068.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0079.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0080.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0085.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0086.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0136.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0264.htmlhttp://www.debian.org/security/2015/dsa-3144http://www.debian.org/security/2015/dsa-3147http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.securityfocus.com/bid/72175http://www.securitytracker.com/id/1031580http://www.ubuntu.com/usn/USN-2486-1http://www.ubuntu.com/usn/USN-2487-1http://www.vmware.com/security/advisories/VMSA-2015-0003.htmlhttps://security.gentoo.org/glsa/201507-14https://security.gentoo.org/glsa/201603-14https://www-304.ibm.com/support/docview.wss?uid=swg21695474
2015-01-21
Published