Summary
The host is installed with Oracle Java SE JRE
and is prone to multiple unspecified vulnerabilities.
Impact
Successful exploitation will allow attackers
to bypass security restrictions, disclose sensitive information, manipulate certain data, conduct IP spoofing attacks or hijack a mutually authenticated session.
Impact Level: Application.
Solution
Apply the patch from below link,
http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
Insight
Multiple flaws exist due to,
- An unspecified error in share/classes/javax/crypto/CipherInputStream.java script related to streaming of input cipher streams.
- An error in share/classes/java/util/ResourceBundle.java script related to property processing and handling of names.
- An error in the 'LogRecord::readObject' function in classes/java/util/logging/LogRecord.java related to handling of resource bundles.
- An error related to the wrapping of datagram sockets in the DatagramSocket implementation.
- An error in share/classes/java/util/logging/Logger.java related to missing permission checks of logger resources.
- An error related to handling of server certificate changes during SSL/TLS renegotiation.
- An error within the 2D subcomponent of the client deployment.
Affected
Oracle Java SE 5 update 71 and prior,
6 update 81 and prior, 7 update 67 and prior, and 8 update 20 and prior on Windows
Detection
Get the installed version of Oracle Java
SE JRE with the help of detect NVT and check the version is vulnerable or not.
References
Severity
Classification
-
CVE CVE-2014-6457, CVE-2014-6502, CVE-2014-6506, CVE-2014-6511, CVE-2014-6512, CVE-2014-6531, CVE-2014-6558 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Apple Safari 'background' Remote Denial Of Service Vulnerability
- Apple Safari Multiple Memory Corruption Vulnerabilities-01 Aug14 (Mac OS X)
- Apple Safari Webkit Multiple Vulnerabilities - June13 (Mac OS X)
- aMSN session hijack vulnerability (Windows)
- Adobe Flash Media Server Video Stream Capture Security Issue