1
PublicDateAtUSN: 2014-01-15
2
Candidate: CVE-2014-0368
5
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0368
6
https://rhn.redhat.com/errata/RHSA-2014-0026.html
7
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
8
https://usn.ubuntu.com/usn/usn-2089-1
9
https://usn.ubuntu.com/usn/usn-2124-1
11
Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45, and
12
Java SE Embedded 7u45, allows remote attackers to affect confidentiality
13
via unknown vectors related to Networking. NOTE: the previous information
14
is from the January 2014 CPU. Oracle has not commented on third-party
15
claims that the issue is related to incorrect permission checks when
16
listening on a socket, which allows attackers to escape the sandbox.
19
mdeslaur> in lucid+, NetX and the plugin moved to the icedtea-web package
20
jdstrand> sun-java6 is not redistributable, no longer in the archive and
22
jdstrand> sun-java5 is EOL upstream and no longer tracked
29
upstream_openjdk-6: needs-triage
30
lucid_openjdk-6: released (6b30-1.13.1-1ubuntu2~0.10.04.1)
31
precise_openjdk-6: released (6b30-1.13.1-1ubuntu2~0.12.04.1)
32
quantal_openjdk-6: released (6b30-1.13.1-1ubuntu2~0.12.10.1)
33
raring_openjdk-6: deferred (2014-01-15)
34
saucy_openjdk-6: released (6b30-1.13.1-1ubuntu2~0.13.10.1)
35
devel_openjdk-6: not-affected (6b30-1.13.1-1ubuntu1)
38
upstream_openjdk-7: released (7u51-2.4.4-1)
40
precise_openjdk-7: released (7u51-2.4.4-0ubuntu0.12.04.2)
41
quantal_openjdk-7: released (7u51-2.4.4-0ubuntu0.12.10.2)
42
raring_openjdk-7: released (7u51-2.4.4-0ubuntu0.13.04.2)
43
saucy_openjdk-7: released (7u51-2.4.4-0ubuntu0.13.10.1)
44
devel_openjdk-7: not-affected (7u51-2.4.4-1ubuntu1)