Bug 1053010 (CVE-2014-0411) - CVE-2014-0411 OpenJDK: TLS/SSL handshake timing issues (JSSE, 8023069)
Summary: CVE-2014-0411 OpenJDK: TLS/SSL handshake timing issues (JSSE, 8023069)
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2014-0411
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1049945
TreeView+ depends on / blocked
 
Reported: 2014-01-14 15:06 UTC by Tomas Hoger
Modified: 2021-02-17 06:59 UTC (History)
6 users (show)

Fixed In Version: icedtea 2.4.4, icedtea 2.3.13, icedtea 1.12.8, icedtea 1.13.1
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2014-02-06 15:41:45 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:0026 0 normal SHIPPED_LIVE Critical: java-1.7.0-openjdk security update 2014-01-15 05:59:20 UTC
Red Hat Product Errata RHSA-2014:0027 0 normal SHIPPED_LIVE Important: java-1.7.0-openjdk security update 2014-01-15 05:59:08 UTC
Red Hat Product Errata RHSA-2014:0030 0 normal SHIPPED_LIVE Critical: java-1.7.0-oracle security update 2014-01-16 00:17:27 UTC
Red Hat Product Errata RHSA-2014:0097 0 normal SHIPPED_LIVE Important: java-1.6.0-openjdk security update 2014-01-28 00:54:36 UTC
Red Hat Product Errata RHSA-2014:0134 0 normal SHIPPED_LIVE Critical: java-1.7.0-ibm security update 2014-02-05 00:35:22 UTC
Red Hat Product Errata RHSA-2014:0135 0 normal SHIPPED_LIVE Critical: java-1.6.0-ibm security update 2014-02-05 00:34:32 UTC
Red Hat Product Errata RHSA-2014:0136 0 normal SHIPPED_LIVE Important: java-1.5.0-ibm security update 2014-02-05 00:34:19 UTC
Red Hat Product Errata RHSA-2014:0414 0 normal SHIPPED_LIVE Important: java-1.6.0-sun security update 2017-12-15 19:38:49 UTC
Red Hat Product Errata RHSA-2014:0705 0 normal SHIPPED_LIVE Critical: java-1.7.1-ibm security update 2014-06-10 17:07:11 UTC
Red Hat Product Errata RHSA-2014:0982 0 normal SHIPPED_LIVE Low: Red Hat Network Satellite server IBM Java Runtime security update 2014-07-29 19:40:11 UTC

Description Tomas Hoger 2014-01-14 15:06:59 UTC
It was discovered that the JSSE component in OpenJDK could leak some timing information during the TLS/SSL handshake.  This could possibly lead to disclosure of some information about negotiated encryption keys.

Comment 1 Tomas Hoger 2014-01-14 21:26:09 UTC
Public now via Oracle CPU January 2014.  Fixed in Oracle JDK 7u51, 6u71 and 5.0u61.

External References:

http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html

Comment 2 errata-xmlrpc 2014-01-15 01:03:19 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2014:0027 https://rhn.redhat.com/errata/RHSA-2014-0027.html

Comment 3 errata-xmlrpc 2014-01-15 01:03:38 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2014:0026 https://rhn.redhat.com/errata/RHSA-2014-0026.html

Comment 4 errata-xmlrpc 2014-01-15 19:18:49 UTC
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 5
  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2014:0030 https://rhn.redhat.com/errata/RHSA-2014-0030.html

Comment 5 Tomas Hoger 2014-01-16 08:53:56 UTC
OpenJDK7 upstream commit:

http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/d533e96c7acc

Comment 6 errata-xmlrpc 2014-01-27 19:56:56 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5
  Red Hat Enterprise Linux 6

Via RHSA-2014:0097 https://rhn.redhat.com/errata/RHSA-2014-0097.html

Comment 8 errata-xmlrpc 2014-02-04 19:37:27 UTC
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 5
  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2014:0136 https://rhn.redhat.com/errata/RHSA-2014-0136.html

Comment 9 errata-xmlrpc 2014-02-04 19:38:44 UTC
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 5
  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2014:0135 https://rhn.redhat.com/errata/RHSA-2014-0135.html

Comment 10 errata-xmlrpc 2014-02-04 19:42:43 UTC
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 5
  Supplementary for Red Hat Enterprise Linux 6

Via RHSA-2014:0134 https://rhn.redhat.com/errata/RHSA-2014-0134.html

Comment 11 errata-xmlrpc 2014-04-17 11:43:14 UTC
This issue has been addressed in following products:

  Oracle Java for Red Hat Enterprise Linux 6
  Oracle Java for Red Hat Enterprise Linux 5

Via RHSA-2014:0414 https://rhn.redhat.com/errata/RHSA-2014-0414.html

Comment 12 errata-xmlrpc 2014-06-10 13:13:20 UTC
This issue has been addressed in following products:

  Supplementary for Red Hat Enterprise Linux 7

Via RHSA-2014:0705 https://rhn.redhat.com/errata/RHSA-2014-0705.html

Comment 13 errata-xmlrpc 2014-07-29 15:41:43 UTC
This issue has been addressed in following products:

  Red Hat Network Satellite Server v 5.4
  Red Hat Network Satellite Server v 5.5
  Red Hat Satellite Server v 5.6

Via RHSA-2014:0982 https://rhn.redhat.com/errata/RHSA-2014-0982.html


Note You need to log in before you can comment on or make changes to this bug.