Bug 1183646 (CVE-2014-6591)
Summary: | CVE-2014-6591 ICU: font parsing OOB read (OpenJDK 2D, 8056276) | ||||||
---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Tomas Hoger <thoger> | ||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
Status: | CLOSED ERRATA | QA Contact: | |||||
Severity: | low | Docs Contact: | |||||
Priority: | low | ||||||
Version: | unspecified | CC: | ahughes, caolanm, dbhole, denis.arnaud_fedora, erack, erik-fedora, jerboaa, jvanek, omajid, sbaiduzh, security-response-team, tuxator | ||||
Target Milestone: | --- | Keywords: | Reopened, Security | ||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||
Doc Text: |
A boundary check flaw was found in the font parsing code in the 2D component in OpenJDK. A specially crafted font file could allow an untrusted Java application or applet to disclose portions of the Java Virtual Machine memory.
|
Story Points: | --- | ||||
Clone Of: | Environment: | ||||||
Last Closed: | 2015-02-24 14:30:34 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | 1184811, 1184812, 1184813 | ||||||
Bug Blocks: | 957599, 1179762 | ||||||
Attachments: |
|
Description
Tomas Hoger
2015-01-19 11:42:34 UTC
Created attachment 981490 [details]
OpenJDK-8 patch
Public now via Oracle Critical Patch Update - January 2015. Fixed in Oracle Java SE 5.0u81, 6u91, 7u75, and 8u31. External References: http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html#AppendixJAVA This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Via RHSA-2015:0068 https://rhn.redhat.com/errata/RHSA-2015-0068.html This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2015:0069 https://rhn.redhat.com/errata/RHSA-2015-0069.html This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 Via RHSA-2015:0067 https://rhn.redhat.com/errata/RHSA-2015-0067.html Upstream OpenJDK commits: http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/be61bf86aee9 http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/2dfb4ef6c76d Created mingw-icu tracking bugs for this issue: Affects: fedora-all [bug 1184812] Affects: epel-7 [bug 1184813] Created icu tracking bugs for this issue: Affects: fedora-all [bug 1184811] This issue has been addressed in the following products: Oracle Java for Red Hat Enterprise Linux 6 Via RHSA-2015:0080 https://rhn.redhat.com/errata/RHSA-2015-0080.html This issue has been addressed in the following products: Oracle Java for Red Hat Enterprise Linux 7 Oracle Java for Red Hat Enterprise Linux 5 Oracle Java for Red Hat Enterprise Linux 6 Via RHSA-2015:0079 https://rhn.redhat.com/errata/RHSA-2015-0079.html This issue was fixed in IcedTea6 1.13.6 and IcedTea7 2.5.4: http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2015-January/030488.html http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2015-January/030469.html This issue has been addressed in the following products: Oracle Java for Red Hat Enterprise Linux 7 Oracle Java for Red Hat Enterprise Linux 6 Oracle Java for Red Hat Enterprise Linux 5 Via RHSA-2015:0086 https://rhn.redhat.com/errata/RHSA-2015-0086.html This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 Via RHSA-2015:0085 https://rhn.redhat.com/errata/RHSA-2015-0085.html This issue has been addressed in the following products: Supplementary for Red Hat Enterprise Linux 6 Supplementary for Red Hat Enterprise Linux 5 Via RHSA-2015:0136 https://rhn.redhat.com/errata/RHSA-2015-0136.html This issue has been addressed in the following products: Supplementary for Red Hat Enterprise Linux 5 Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2015:0135 https://rhn.redhat.com/errata/RHSA-2015-0135.html This issue has been addressed in the following products: Supplementary for Red Hat Enterprise Linux 5 Via RHSA-2015:0134 https://rhn.redhat.com/errata/RHSA-2015-0134.html This issue has been addressed in the following products: Supplementary for Red Hat Enterprise Linux 7 Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2015:0133 https://rhn.redhat.com/errata/RHSA-2015-0133.html This issue has been addressed in the following products: Red Hat Satellite Server v 5.7 Via RHSA-2015:0263 https://rhn.redhat.com/errata/RHSA-2015-0263.html This issue has been addressed in the following products: Red Hat Satellite Server v 5.6 Via RHSA-2015:0264 https://rhn.redhat.com/errata/RHSA-2015-0264.html (In reply to Tomas Hoger from comment #7) > Upstream OpenJDK commits: > > http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/be61bf86aee9 > http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/2dfb4ef6c76d ICU upstream commit: http://bugs.icu-project.org/trac/changeset/37086 icu-50.1.2-11.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report. icu-52.1-5.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report. icu-54.1-5.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report. icu-54.1-4.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report. |