A flaw was found in the way the Libraries component of OpenJDK handled certificate revocation lists (CRL). In certain cases, CRL checking code could fail to report that a certificate was revoked, causing the application to accept it as trusted.
Public now via Oracle Critical Patch Update - October 2015. Fixed in Oracle Java SE 8u65. External References: http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html#AppendixJAVA
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 Via RHSA-2015:1919 https://rhn.redhat.com/errata/RHSA-2015-1919.html
This issue has been addressed in the following products: Oracle Java for Red Hat Enterprise Linux 7 Oracle Java for Red Hat Enterprise Linux 6 Via RHSA-2015:1926 https://rhn.redhat.com/errata/RHSA-2015-1926.html
OpenJDK8 upstream commit: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/cc102fdacea5