| Unspecified vulnerability in the Java Runtime Environment (JRE)
component in Oracle Java SE 7 through Update 11, 6 through Update 38,
5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7,
allows remote attackers to affect availability via vectors related to
JSSE. NOTE: the previous information is from the February 2013 CPU.
Oracle has not commented on claims from another vendor that this
issue is related to CPU consumption in the SSL/TLS implementation via
a large number of ClientHello packets that are not properly handled
by (1) ClientHandshaker.java and (2) ServerHandshaker.java.
|