CVE-2015-2601
Public on 2015-07-16
Modified on 2015-08-24
Description
It was discovered that the JCE component in OpenJDK failed to use constant time comparisons in multiple cases. An attacker could possibly use these flaws to disclose sensitive information by measuring the time used to perform operations using these non-constant time comparisons.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
HAQM Linux 1 | java-1.6.0-openjdk | 2015-08-24 | ALAS-2015-586 | Fixed |
HAQM Linux 1 | java-1.7.0-openjdk | 2015-07-22 | ALAS-2015-570 | Fixed |
HAQM Linux 1 | java-1.8.0-openjdk | 2015-07-22 | ALAS-2015-571 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
HAQM Linux | CVSSv2 | 5.0 | AV:N/AC:L/Au:N/C:P/I:N/A:N |
NVD | CVSSv2 | 5.0 | AV:N/AC:L/Au:N/C:P/I:N/A:N |