{"id":"USN-2187-1","summary":"openjdk-7 vulnerabilities","details":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure, data integrity and availability. An attacker could\nexploit these to cause a denial of service or expose sensitive data over\nthe network. (CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-0452,\nCVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,\nCVE-2014-0461, CVE-2014-2397, CVE-2014-2402, CVE-2014-2412, CVE-2014-2414,\nCVE-2014-2421, CVE-2014-2423, CVE-2014-2427)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto expose sensitive data over the network. (CVE-2014-0453, CVE-2014-0460)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2014-0459)\n\nJakub Wilk discovered that the OpenJDK JRE incorrectly handled temporary\nfiles. A local attacker could possibly use this issue to overwrite\narbitrary files. In the default installation of Ubuntu, this should be\nprevented by the Yama link restrictions. (CVE-2014-1876)\n\nTwo vulnerabilities were discovered in the OpenJDK JRE related to data\nintegrity. (CVE-2014-2398, CVE-2014-2413)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure. An attacker could exploit this to expose sensitive data over\nthe network. (CVE-2014-2403)\n","modified":"2026-04-27T15:17:33.988312726Z","published":"2014-04-30T14:32:48Z","related":["UBUNTU-CVE-2014-0429","UBUNTU-CVE-2014-0446","UBUNTU-CVE-2014-0451","UBUNTU-CVE-2014-0452","UBUNTU-CVE-2014-0453","UBUNTU-CVE-2014-0454","UBUNTU-CVE-2014-0455","UBUNTU-CVE-2014-0456","UBUNTU-CVE-2014-0457","UBUNTU-CVE-2014-0458","UBUNTU-CVE-2014-0459","UBUNTU-CVE-2014-0460","UBUNTU-CVE-2014-0461","UBUNTU-CVE-2014-1876","UBUNTU-CVE-2014-2397","UBUNTU-CVE-2014-2398","UBUNTU-CVE-2014-2402","UBUNTU-CVE-2014-2403","UBUNTU-CVE-2014-2412","UBUNTU-CVE-2014-2413","UBUNTU-CVE-2014-2414","UBUNTU-CVE-2014-2421","UBUNTU-CVE-2014-2423","UBUNTU-CVE-2014-2427"],"upstream":["CVE-2014-0429","CVE-2014-0446","CVE-2014-0451","CVE-2014-0452","CVE-2014-0453","CVE-2014-0454","CVE-2014-0455","CVE-2014-0456","CVE-2014-0457","CVE-2014-0458","CVE-2014-0459","CVE-2014-0460","CVE-2014-0461","CVE-2014-1876","CVE-2014-2397","CVE-2014-2398","CVE-2014-2402","CVE-2014-2403","CVE-2014-2412","CVE-2014-2413","CVE-2014-2414","CVE-2014-2421","CVE-2014-2423","CVE-2014-2427","UBUNTU-CVE-2014-0429","UBUNTU-CVE-2014-0446","UBUNTU-CVE-2014-0451","UBUNTU-CVE-2014-0452","UBUNTU-CVE-2014-0453","UBUNTU-CVE-2014-0454","UBUNTU-CVE-2014-0455","UBUNTU-CVE-2014-0456","UBUNTU-CVE-2014-0457","UBUNTU-CVE-2014-0458","UBUNTU-CVE-2014-0459","UBUNTU-CVE-2014-0460","UBUNTU-CVE-2014-0461","UBUNTU-CVE-2014-1876","UBUNTU-CVE-2014-2397","UBUNTU-CVE-2014-2398","UBUNTU-CVE-2014-2402","UBUNTU-CVE-2014-2403","UBUNTU-CVE-2014-2412","UBUNTU-CVE-2014-2413","UBUNTU-CVE-2014-2414","UBUNTU-CVE-2014-2421","UBUNTU-CVE-2014-2423","UBUNTU-CVE-2014-2427"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-2187-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-0429"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-0446"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-0451"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-0452"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-0453"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-0454"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-0455"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-0456"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-0457"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-0458"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-0459"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-0460"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-0461"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-1876"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-2397"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-2398"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-2402"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-2403"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-2412"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-2413"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-2414"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-2421"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-2423"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2014-2427"},{"type":"REPORT","url":"https://launchpad.net/bugs/1283828"}],"affected":[{"package":{"name":"openjdk-7","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/openjdk-7@7u55-2.4.7-1ubuntu1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7u55-2.4.7-1ubuntu1"}]}],"versions":["7u25-2.3.12-4ubuntu3","7u25-2.3.12-4ubuntu5","7u45-2.4.3-3ubuntu1","7u45-2.4.3-3ubuntu2","7u45-2.4.3-4ubuntu1","7u45-2.4.3-4ubuntu2","7u51-2.4.4-1ubuntu1","7u51-2.4.5-1ubuntu1","7u51-2.4.6~pre1-1ubuntu2","7u51-2.4.6-1ubuntu3","7u51-2.4.6-1ubuntu4"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"7u55-2.4.7-1ubuntu1","binary_name":"icedtea-7-jre-jamvm"},{"binary_version":"7u55-2.4.7-1ubuntu1","binary_name":"openjdk-7-demo"},{"binary_version":"7u55-2.4.7-1ubuntu1","binary_name":"openjdk-7-jdk"},{"binary_version":"7u55-2.4.7-1ubuntu1","binary_name":"openjdk-7-jre"},{"binary_version":"7u55-2.4.7-1ubuntu1","binary_name":"openjdk-7-jre-headless"},{"binary_version":"7u55-2.4.7-1ubuntu1","binary_name":"openjdk-7-jre-lib"},{"binary_version":"7u55-2.4.7-1ubuntu1","binary_name":"openjdk-7-jre-zero"},{"binary_version":"7u55-2.4.7-1ubuntu1","binary_name":"openjdk-7-source"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-2187-1.json","cves_map":{"cves":[{"severity":[{"type":"Ubuntu","score":"medium"}],"id":"CVE-2014-0429"},{"id":"CVE-2014-0446","severity":[{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2014-0451","severity":[{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"Ubuntu","score":"medium"}],"id":"CVE-2014-0452"},{"id":"CVE-2014-0453","severity":[{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2014-0454","severity":[{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2014-0455","severity":[{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"Ubuntu","score":"medium"}],"id":"CVE-2014-0456"},{"id":"CVE-2014-0457","severity":[{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2014-0458","severity":[{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2014-0459","severity":[{"type":"Ubuntu","score":"low"}]},{"id":"CVE-2014-0460","severity":[{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2014-0461","severity":[{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2014-1876","severity":[{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2014-2397","severity":[{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2014-2398","severity":[{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2014-2402","severity":[{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"Ubuntu","score":"medium"}],"id":"CVE-2014-2403"},{"id":"CVE-2014-2412","severity":[{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2014-2413","severity":[{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2014-2414","severity":[{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2014-2421","severity":[{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2014-2423","severity":[{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"Ubuntu","score":"medium"}],"id":"CVE-2014-2427"}],"ecosystem":"Ubuntu:14.04:LTS"}}}],"schema_version":"1.7.5"}