LWN.net Logo

java: sandbox restriction bypass

Package(s):java CVE #(s):CVE-2013-1484 CVE-2013-1485
Created:February 20, 2013 Updated:February 21, 2013
Description: From the Red Hat advisory:

Improper permission check issues were discovered in the JMX and Libraries components in OpenJDK. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. (CVE-2013-1484)

An improper permission check issue was discovered in the Libraries component in OpenJDK. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions. (CVE-2013-1485)

Alerts:
Red Hat RHSA-2013:0275-01 2013-02-20
Red Hat RHSA-2013:0532-01 2013-02-20
Scientific Linux SL-java-20130220 2013-02-20
CentOS CESA-2013:0275 2013-02-20
CentOS CESA-2013:0275 2013-02-20
Oracle ELSA-2013-0275 2013-02-20
Oracle ELSA-2013-0275 2013-02-21
Fedora FEDORA-2013-2764 2013-02-21
Fedora FEDORA-2013-2813 2013-02-21
Ubuntu USN-1735-1 2013-02-21
Mageia MGASA-2013-0084 2013-03-03
Red Hat RHSA-2013:0626-01 2013-03-11
SUSE SUSE-SU-2013:0440-1 2013-03-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds