Bug 1097345 (CVE-2014-0878)
| Summary: | CVE-2014-0878 IBM JDK: Vulnerability in the IBMSecureRandom implementation of the IBMJCE and IBMSecureRandom cryptographic providers | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Vasyl Kaigorodov <vkaigoro> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | dbhole, jfabriko, jkurik, jvanek |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2014-05-30 08:40:18 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 1082776 | ||
|
Description
Vasyl Kaigorodov
2014-05-13 15:18:47 UTC
IBM mentions the following workaround: "For CVE-2014-0878, use the IBMSecureRandom implementation from the IBMJCEFIPS cryptographic provider. Or, if using the IBMJCE cryptographic provider, use the SHA1PRNG or the DRBG family of secure random number generators. Or, if using the IBMSecureRandom cryptographic provider, use the SHA1PRNG secure random number generator." References: http://www-01.ibm.com/support/docview.wss?uid=swg21672043 Red Hat Enterprise Linux Supplementary updates to fixed IBM Java SE 5.0, 6, and 7 versions were released before this CVE was made public. The list of relevant errata can be found on the CVE page: https://access.redhat.com/security/cve/CVE-2014-0878 This issue has been addressed in following products: Red Hat Network Satellite Server v 5.4 Red Hat Network Satellite Server v 5.5 Red Hat Satellite Server v 5.6 Via RHSA-2014:0982 https://rhn.redhat.com/errata/RHSA-2014-0982.html |