A flaw was found in the way the Hotspot component in OpenJDK handled phantom references. An untrusted Java application or applet could use this flaw to corrupt the Java Virtual Machine memory and, possibly, execute arbitrary code, bypassing Java sandbox restrictions.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 1 | java-1.6.0-openjdk | 2015-04-23 00:44 | ALAS-2015-515 |
Amazon Linux 1 | java-1.7.0-openjdk | 2015-04-23 00:44 | ALAS-2015-516 |
Amazon Linux 1 | java-1.8.0-openjdk | 2015-05-05 15:44 | ALAS-2015-517 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv2 | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
NVD | CVSSv2 | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |