4
CVSSv2

CVE-2014-6593

Published: 21/01/2015 Updated: 13/05/2022
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
VMScore: 405
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4 allows remote malicious users to affect confidentiality and integrity via vectors related to JSSE.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle jrockit r27.8.4

oracle jrockit r28.3.4

oracle jdk 1.8.0

oracle jdk 1.7.0

oracle jdk 1.5.0

oracle jdk 1.6.0

oracle jre 1.5.0

oracle jre 1.6.0

oracle jre 1.7.0

oracle jre 1.8.0

Vendor Advisories

Several security issues were fixed in OpenJDK 7 ...
Several security issues were fixed in OpenJDK 6 ...
Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in the execution of arbitrary code, information disclosure or denial of service For the stable distribution (wheezy), these problems have been fixed in version 7u75-254-1~deb7u1 For the upcoming stable distribution (jessie), these p ...
Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in the execution of arbitrary code, information disclosure or denial of service For the stable distribution (wheezy), these problems have been fixed in version 6b34-1136-1~deb7u1 We recommend that you upgrade your openjdk-6 packages ...
Synopsis Critical: java-160-ibm security update Type/Severity Security Advisory: Critical Topic Updated java-160-ibm packages that fix several security issues are nowavailable for Red Hat Enterprise Linux 5 and 6 SupplementaryRed Hat Product Security has rated this update as having Critical securityimp ...
Synopsis Important: java-150-ibm security update Type/Severity Security Advisory: Important Topic Updated java-150-ibm packages that fix several security issues are nowavailable for Red Hat Enterprise Linux 5 and 6 SupplementaryRed Hat Product Security has rated this update as having Important security ...
Synopsis Critical: java-170-oracle security update Type/Severity Security Advisory: Critical Topic Updated java-170-oracle packages that fix several security issues are nowavailable for Oracle Java for Red Hat Enterprise Linux 5, 6, and 7Red Hat Product Security has rated this update as having Critical ...
Synopsis Important: java-180-openjdk security update Type/Severity Security Advisory: Important Topic Updated java-180-openjdk packages that fix multiple security issues arenow available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having Important securityimpact Com ...
Synopsis Critical: java-170-ibm security update Type/Severity Security Advisory: Critical Topic Updated java-170-ibm packages that fix several security issues are nowavailable for Red Hat Enterprise Linux 5 SupplementaryRed Hat Product Security has rated this update as having Critical securityimpact C ...
Synopsis Important: java-170-openjdk security update Type/Severity Security Advisory: Important Topic Updated java-170-openjdk packages that fix multiple security issues arenow available for Red Hat Enterprise Linux 5Red Hat Product Security has rated this update as having Important securityimpact Com ...
Synopsis Critical: java-180-oracle security update Type/Severity Security Advisory: Critical Topic Updated java-180-oracle packages that fix several security issues are nowavailable for Oracle Java for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having Critical securityi ...
Synopsis Important: java-160-openjdk security update Type/Severity Security Advisory: Important Topic Updated java-160-openjdk packages that fix multiple security issues arenow available for Red Hat Enterprise Linux 5, 6, and 7Red Hat Product Security has rated this update as having Important securityi ...
Synopsis Critical: java-171-ibm security update Type/Severity Security Advisory: Critical Topic Updated java-171-ibm packages that fix several security issues are nowavailable for Red Hat Enterprise Linux 6 and 7 SupplementaryRed Hat Product Security has rated this update as having Critical securityimp ...
Synopsis Low: Red Hat Satellite IBM Java Runtime security update Type/Severity Security Advisory: Low Topic Updated java-160-ibm packages that fix several security issues are nowavailable for Red Hat Satellite 56Red Hat Product Security has rated this update as having Low securityimpact Common Vulnerab ...
Synopsis Low: Red Hat Satellite IBM Java Runtime security update Type/Severity Security Advisory: Low Topic Updated java-160-ibm packages that fix several security issues are nowavailable for Red Hat Satellite 57Red Hat Product Security has rated this update as having Low securityimpact Common Vulnerab ...
Synopsis Critical: java-170-openjdk security update Type/Severity Security Advisory: Critical Topic Updated java-170-openjdk packages that fix multiple security issues arenow available for Red Hat Enterprise Linux 6 and 7Red Hat Product Security has rated this update as having Critical securityimpact ...
Synopsis Important: java-160-sun security update Type/Severity Security Advisory: Important Topic Updated java-160-sun packages that fix several security issues are nowavailable for Oracle Java for Red Hat Enterprise Linux 5, 6, and 7Red Hat Product Security has rated this update as having Important se ...
Multiple flaws were found in the way the Hotspot component in OpenJDK verified bytecode from the class files, and in the way this component generated code for bytecode An untrusted Java application or applet could possibly use these flaws to bypass Java sandbox restrictions (CVE-2014-6601, CVE-2015-0437) Multiple improper permission check issues ...
A flaw was found in the way the Hotspot component in OpenJDK verified bytecode from the class files An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions (CVE-2014-6601) Multiple improper permission check issues were discovered in the JAX-WS, and RMI components in OpenJDK An untrusted Java appli ...
A flaw was found in the way the Hotspot component in OpenJDK verified bytecode from the class files An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions (CVE-2014-6601) Multiple improper permission check issues were discovered in the JAX-WS, and RMI components in OpenJDK An untrusted Java appli ...
It was discovered that the SSL/TLS implementation in the JSSE component in OpenJDK failed to properly check whether the ChangeCipherSpec was received during the SSL/TLS connection handshake An MITM attacker could possibly use this flaw to force a connection to be established without encryption being enabled ...

Exploits

#!/usr/bin/env ruby # encoding: ASCII-8BIT # By Ramon de C Valle This work is dedicated to the public domain require 'openssl' require 'optparse' require 'socket' Version = [0, 0, 1] Release = nil def prf(secret, label, seed) if secretempty? s1 = s2 = '' else length = ((secretlength * 10) / 2)ceil s1 = secret[0(length - 1 ...

References

NVD-CWE-noinfohttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.securityfocus.com/bid/72169http://www.securitytracker.com/id/1031580https://www-304.ibm.com/support/docview.wss?uid=swg21695474http://www.debian.org/security/2015/dsa-3147http://marc.info/?l=bugtraq&m=142496355704097&w=2http://www.debian.org/security/2015/dsa-3144http://www.ubuntu.com/usn/USN-2487-1http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00001.htmlhttp://www.ubuntu.com/usn/USN-2486-1http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00024.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0264.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0080.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0068.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0136.htmlhttp://marc.info/?l=bugtraq&m=142607790919348&w=2http://rhn.redhat.com/errata/RHSA-2015-0079.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0085.htmlhttp://h20564.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04583581http://rhn.redhat.com/errata/RHSA-2015-0086.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00018.htmlhttp://www.vmware.com/security/advisories/VMSA-2015-0003.htmlhttps://security.gentoo.org/glsa/201603-14http://packetstormsecurity.com/files/134251/Java-Secure-Socket-Extension-JSSE-SKIP-TLS.htmlhttps://www.exploit-db.com/exploits/38641/https://security.gentoo.org/glsa/201507-14https://kc.mcafee.com/corporate/index?page=content&id=SB10104https://nvd.nist.govhttps://usn.ubuntu.com/2487-1/https://www.exploit-db.com/exploits/38641/https://access.redhat.com/security/cve/cve-2014-6593