CVE-2015-2632
icu - security update
EPSS 1.7%
Description
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45 allows remote attackers to affect confidentiality via unknown vectors related to 2D.
How to fix CVE-2015-2632
To remediate CVE-2015-2632, upgrade the affected package to a fixed version below.
- Debian/icu—upgrade to 55.1-7 or later
- Debian/icu—upgrade to 4.4.1-8+squeeze5 or later
- Debian/icu—upgrade to 4.8.1.1-12+deb7u4 or later
Is CVE-2015-2632 being exploited?
Low — EPSS is 1.7%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 55.1-7
- from 0, < 4.4.1-8+squeeze5
- from 0, < 4.8.1.1-12+deb7u4