It was discovered that the JCE component in OpenJDK failed to use constant time comparisons in multiple cases. An attacker could possibly use these flaws to disclose sensitive information by measuring the time used to perform operations using these non-constant time comparisons.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 1 | java-1.6.0-openjdk | 2015-08-24 22:26 | ALAS-2015-586 |
Amazon Linux 1 | java-1.7.0-openjdk | 2015-07-22 10:00 | ALAS-2015-570 |
Amazon Linux 1 | java-1.8.0-openjdk | 2015-07-22 10:00 | ALAS-2015-571 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv2 | 5.0 | AV:N/AC:L/Au:N/C:P/I:N/A:N |
NVD | CVSSv2 | 5.0 | AV:N/AC:L/Au:N/C:P/I:N/A:N |