Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1088039 - (CVE-2014-0463, CVE-2014-0464, CVE-2014-2410) Oracle JDK: unspecified vulnerabilities fixed in 8u5 (JavaFX, Scripting)
Oracle JDK: unspecified vulnerabilities fixed in 8u5 (JavaFX, Scripting)
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
urgent Severity urgent
: ---
: ---
Assigned To: Red Hat Product Security
impact=critical,public=20140415,repor...
: Security
Depends On:
Blocks: 1082776
  Show dependency treegraph
 
Reported: 2014-04-15 17:53 EDT by Tomas Hoger
Modified: 2018-07-17 06:09 EDT (History)
6 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-04-15 17:56:57 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Tomas Hoger 2014-04-15 17:53:50 EDT
Oracle Java SE 8u5 fixes an unspecified vulnerability in the JavaFX component (CVE-2014-2410).  Upstream has CVSSv2 scored this issue as: 9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C

External Reference:

http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html#AppendixJAVA
Comment 1 Tomas Hoger 2014-04-15 17:56:57 EDT
There are two other issues fixed via Oracle Critical Patch Update Advisory - April 2014 that only affected Oracle Java SE 8 and not previous versions:

CVE-2014-0463	Scripting	4.3/AV:N/AC:M/Au:N/C:P/I:N/A:N
CVE-2014-0464	Scripting	4.3/AV:N/AC:M/Au:N/C:P/I:N/A:N

Oracle Java SE 8 is not currently shipped as part of any Red Hat product.

Note You need to log in before you can comment on or make changes to this bug.