CVE-2015-2590
Publication date 16 July 2015
Last updated 21 August 2024
Ubuntu priority
Cvss 3 Severity Score
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.
Status
Package | Ubuntu Release | Status |
---|---|---|
openjdk-6 | ||
14.04 LTS trusty |
Fixed 6b36-1.13.8-0ubuntu1~14.04
|
|
openjdk-7 | ||
14.04 LTS trusty |
Fixed 7u79-2.5.6-0ubuntu1.14.04.1
|
|
openjdk-8 | ||
14.04 LTS trusty | Not in release | |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 9.8 · Critical |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References
Related Ubuntu Security Notices (USN)
- 2696-1
- OpenJDK 7 vulnerabilities
- 30 July 2015
- USN-2706-1
- OpenJDK 6 vulnerabilities
- 6 August 2015
- USN-2696-1
- OpenJDK 7 vulnerabilities
- 30 July 2015