CVE-2013-0444

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient checks for cached results" by the Java Beans MethodFinder, which might allow attackers to access methods that should only be accessible to privileged code.
References
Link Resource
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907218
http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ce04db4aba39
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html
http://marc.info/?l=bugtraq&m=136439120408139&w=2
http://marc.info/?l=bugtraq&m=136439120408139&w=2
http://marc.info/?l=bugtraq&m=136733161405818&w=2
http://marc.info/?l=bugtraq&m=136733161405818&w=2
http://rhn.redhat.com/errata/RHSA-2013-0237.html
http://rhn.redhat.com/errata/RHSA-2013-0247.html
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.kb.cert.org/vuls/id/858729 US Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2013:095
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html Vendor Advisory
http://www.us-cert.gov/cas/techalerts/TA13-032A.html US Government Resource
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16614
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19349
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907218
http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ce04db4aba39
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html
http://marc.info/?l=bugtraq&m=136439120408139&w=2
http://marc.info/?l=bugtraq&m=136439120408139&w=2
http://marc.info/?l=bugtraq&m=136733161405818&w=2
http://marc.info/?l=bugtraq&m=136733161405818&w=2
http://rhn.redhat.com/errata/RHSA-2013-0237.html
http://rhn.redhat.com/errata/RHSA-2013-0247.html
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.kb.cert.org/vuls/id/858729 US Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2013:095
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html Vendor Advisory
http://www.us-cert.gov/cas/techalerts/TA13-032A.html US Government Resource
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16614
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19349
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:jre:1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update2:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update3:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update4:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update5:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update6:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update7:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update9:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:oracle:jdk:1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.7.0:update1:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.7.0:update10:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.7.0:update11:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.7.0:update2:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.7.0:update3:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.7.0:update4:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.7.0:update5:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.7.0:update6:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.7.0:update7:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.7.0:update9:*:*:*:*:*:*

History

21 Nov 2024, 01:47

Type Values Removed Values Added
References () http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907218 - () http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907218 -
References () http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ce04db4aba39 - () http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ce04db4aba39 -
References () http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html - () http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html -
References () http://marc.info/?l=bugtraq&m=136439120408139&w=2 - () http://marc.info/?l=bugtraq&m=136439120408139&w=2 -
References () http://marc.info/?l=bugtraq&m=136733161405818&w=2 - () http://marc.info/?l=bugtraq&m=136733161405818&w=2 -
References () http://rhn.redhat.com/errata/RHSA-2013-0237.html - () http://rhn.redhat.com/errata/RHSA-2013-0237.html -
References () http://rhn.redhat.com/errata/RHSA-2013-0247.html - () http://rhn.redhat.com/errata/RHSA-2013-0247.html -
References () http://security.gentoo.org/glsa/glsa-201406-32.xml - () http://security.gentoo.org/glsa/glsa-201406-32.xml -
References () http://www.kb.cert.org/vuls/id/858729 - US Government Resource () http://www.kb.cert.org/vuls/id/858729 - US Government Resource
References () http://www.mandriva.com/security/advisories?name=MDVSA-2013:095 - () http://www.mandriva.com/security/advisories?name=MDVSA-2013:095 -
References () http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html - Vendor Advisory () http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html - Vendor Advisory
References () http://www.us-cert.gov/cas/techalerts/TA13-032A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA13-032A.html - US Government Resource
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16614 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16614 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19349 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19349 -
References () https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056 - () https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056 -

Information

Published : 2013-02-02 00:55

Updated : 2024-11-21 01:47


NVD link : CVE-2013-0444

Mitre link : CVE-2013-0444

CVE.ORG link : CVE-2013-0444


JSON object : View

Products Affected

oracle

  • jdk
  • jre