CVE-2014-2483

NameCVE-2014-2483
DescriptionUnspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-4223. NOTE: the previous information is from the July 2014 CPU. Oracle has not commented on another vendor's claim that the issue is related to improper restriction of the "use of privileged annotations."
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2987-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openjdk-7 (PTS)jessie, jessie (lts)7u321-2.6.28-0+deb8u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
openjdk-6source(unstable)(not affected)
openjdk-7sourcewheezy7u65-2.5.1-2~deb7u1DSA-2987-1
openjdk-7source(unstable)7u65-2.5.1-1

Notes

- openjdk-6 <not-affected> (vulnerable code not present)
http://hg.openjdk.java.net/jdk7u/jdk7u/hotspot/rev/848481af9003

Search for package or bug name: Reporting problems