Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2015-2590

Publication date 16 July 2015

Last updated 21 August 2024


Ubuntu priority

Cvss 3 Severity Score

9.8 · Critical

Score breakdown

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.

Status

Package Ubuntu Release Status
openjdk-6 15.10 wily
Not affected
15.04 vivid
Fixed 6b36-1.13.8-0ubuntu1~15.04.1
14.10 utopic Ignored
14.04 LTS trusty
Fixed 6b36-1.13.8-0ubuntu1~14.04
12.04 LTS precise
Fixed 6b36-1.13.8-0ubuntu1~12.04
openjdk-7 15.10 wily
Not affected
15.04 vivid
Fixed 7u79-2.5.6-0ubuntu1.15.04.1
14.10 utopic Ignored
14.04 LTS trusty
Fixed 7u79-2.5.6-0ubuntu1.14.04.1
12.04 LTS precise
Fixed 7u79-2.5.6-0ubuntu1.12.04.1
openjdk-8 15.10 wily
Fixed 8u66-b17-1
15.04 vivid Ignored
14.10 utopic Ignored
14.04 LTS trusty Not in release
12.04 LTS precise Not in release

Severity score breakdown

Parameter Value
Base score 9.8 · Critical
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Related Ubuntu Security Notices (USN)

    • 2696-1
    • OpenJDK 7 vulnerabilities
    • 30 July 2015
    • USN-2706-1
    • OpenJDK 6 vulnerabilities
    • 6 August 2015
    • USN-2696-1
    • OpenJDK 7 vulnerabilities
    • 30 July 2015

Other references