CVE-2014-2414

NameCVE-2014-2414
DescriptionUnspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXB.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-2912-1, DSA-2923-1
NVD severityhigh (attack range: remote)
Debian/oldstablepackage openjdk-6 is vulnerable.
Debian/stablepackages openjdk-6, openjdk-7 are vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openjdk-6 (PTS)squeeze6b18-1.8.13-0+squeeze2vulnerable
squeeze (security)6b31-1.13.3-1~deb6u1fixed
squeeze (lts)6b34-1.13.6-1~deb6u1fixed
wheezy6b27-1.12.5-1vulnerable
wheezy (security)6b34-1.13.6-1~deb7u1fixed
sid6b34-1.13.6-1fixed
openjdk-7 (PTS)wheezy7u3-2.1.7-1vulnerable
wheezy (security)7u75-2.5.4-1~deb7u1fixed
jessie, sid7u75-2.5.4-2fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
openjdk-6source(unstable)6b31-1.13.3-1high
openjdk-6sourcesqueeze6b31-1.13.3-1~deb6u1highDSA-2912-1
openjdk-6sourcewheezy6b31-1.13.3-1~deb7u1highDSA-2912-1
openjdk-7source(unstable)7u55-2.4.7-1high
openjdk-7sourcewheezy7u55-2.4.7-1~deb7u1highDSA-2923-1

Search for package or bug name: Reporting problems