Red Hat Bugzilla – Bug 1119616
CVE-2014-4268 OpenJDK: Missing file choser access restrictions (Swing, 8035699)
Last modified: 2014-08-06 11:55:41 EDT
It was discovered that the Swing file chooser did not properly restrict access to files. An untrusted Java application or applet could possibly use this flaw to gain access to restricted files.
This only affected OpenJDK code used on Microsoft Windows platform. The OpenJDK packages shipped in Red Hat Enterprise Linux or Fedora were not affected by this issue.
Upstream OpenJDK commit: http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/756071871d61