Summary
The host is installed with Oracle Java SE JRE
and is prone to multiple unspecified vulnerabilities.
Impact
Successful exploitation will allow attackers
to bypass security restrictions, disclose sensitive information, manipulate certain data, conduct IP spoofing attacks or hijack a mutually authenticated session.
Impact Level: Application.
Solution
Apply the patch from below link,
http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
Insight
Multiple flaws exist due to,
- An unspecified error in share/classes/javax/crypto/CipherInputStream.java script related to streaming of input cipher streams.
- An error in share/classes/java/util/ResourceBundle.java script related to property processing and handling of names.
- An error in the 'LogRecord::readObject' function in classes/java/util/logging/LogRecord.java related to handling of resource bundles.
- An error related to the wrapping of datagram sockets in the DatagramSocket implementation.
- An error in share/classes/java/util/logging/Logger.java related to missing permission checks of logger resources.
- An error related to handling of server certificate changes during SSL/TLS renegotiation.
- An error within the 2D subcomponent of the client deployment.
Affected
Oracle Java SE 5 update 71 and prior,
6 update 81 and prior, 7 update 67 and prior, and 8 update 20 and prior on Windows
Detection
Get the installed version of Oracle Java
SE JRE with the help of detect NVT and check the version is vulnerable or not.
References
Severity
Classification
-
CVE CVE-2014-6457, CVE-2014-6502, CVE-2014-6506, CVE-2014-6511, CVE-2014-6512, CVE-2014-6531, CVE-2014-6558 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Arris DOCSIS Password Disclosure
- Apple Safari JavaScript Implementation Information Disclosure Vulnerability (Windows)
- Apple Safari Webcore Webkit 'XSSAuditor.cpp' XSS Vulnerability (Mac OS X)
- Adobe Reader Multiple Vulnerabilities - Aug07 (Mac OS X)
- Apple Safari Multiple Memory Corruption Vulnerabilities-02 Aug14 (Mac OS X)