LWN.net Logo

java: multiple unspecified vulnerabilities

Package(s):java CVE #(s):CVE-2013-0431 CVE-2013-0437 CVE-2013-0444 CVE-2013-0448 CVE-2013-0449 CVE-2013-1479 CVE-2013-1489
Created:February 5, 2013 Updated:March 12, 2013
Description: From the CVE entries:

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490. (CVE-2013-0431)

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. (CVE-2013-0437)

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans. (CVE-2013-0444)

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 allows remote attackers to affect integrity via unknown vectors related to Libraries. (CVE-2013-0448)

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 allows remote attackers to affect confidentiality via unknown vectors related to Deployment. (CVE-2013-0449)

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. (CVE-2013-1479)

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability. (CVE-2013-1489)

Alerts:
Red Hat RHSA-2013:0237-01 2013-02-05
Red Hat RHSA-2013:0247-01 2013-02-08
Scientific Linux SL-java-20130208 2013-02-08
CentOS CESA-2013:0247 2013-02-09
Oracle ELSA-2013-0247 2013-02-09
CentOS CESA-2013:0247 2013-02-09
Oracle ELSA-2013-0247 2013-02-10
Ubuntu USN-1724-1 2013-02-14
Mageia MGASA-2013-0056 2013-02-17
openSUSE openSUSE-SU-2013:0377-1 2013-03-01
Red Hat RHSA-2013:0626-01 2013-03-11
SUSE SUSE-SU-2013:0440-1 2013-03-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds