CVE-2013-2461

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier and 6 Update 45 and earlier; the Oracle JRockit component in Oracle Fusion Middleware R27.7.5 and earlier and R28.2.7 and earlier; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. NOTE: the previous information is from the June and July 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass verification of XML signatures via vectors related to a "Missing check for [a] valid DOMCanonicalizationMethod canonicalization algorithm."
References
Link Resource
http://advisories.mageia.org/MGASA-2013-0185.html Third Party Advisory
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/abe9ea5a50d2 Third Party Advisory
http://marc.info/?l=bugtraq&m=137545505800971&w=2 Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=137545592101387&w=2 Mailing List Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0963.html Third Party Advisory
http://seclists.org/fulldisclosure/2014/Dec/23 Mailing List Third Party Advisory
http://secunia.com/advisories/54154 Third Party Advisory
http://security.gentoo.org/glsa/glsa-201406-32.xml Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2013:183 Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html Vendor Advisory
http://www.securityfocus.com/archive/1/534161/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/60645 Third Party Advisory VDB Entry
http://www.us-cert.gov/ncas/alerts/TA13-169A Third Party Advisory US Government Resource
http://www.vmware.com/security/advisories/VMSA-2014-0012.html Third Party Advisory
https://access.redhat.com/errata/RHSA-2014:0414 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=975126 Issue Tracking Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16887 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19565 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19582 Third Party Advisory
http://advisories.mageia.org/MGASA-2013-0185.html Third Party Advisory
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/abe9ea5a50d2 Third Party Advisory
http://marc.info/?l=bugtraq&m=137545505800971&w=2 Mailing List Third Party Advisory
http://marc.info/?l=bugtraq&m=137545592101387&w=2 Mailing List Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0963.html Third Party Advisory
http://seclists.org/fulldisclosure/2014/Dec/23 Mailing List Third Party Advisory
http://secunia.com/advisories/54154 Third Party Advisory
http://security.gentoo.org/glsa/glsa-201406-32.xml Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2013:183 Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html Vendor Advisory
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html Vendor Advisory
http://www.securityfocus.com/archive/1/534161/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/60645 Third Party Advisory VDB Entry
http://www.us-cert.gov/ncas/alerts/TA13-169A Third Party Advisory US Government Resource
http://www.vmware.com/security/advisories/VMSA-2014-0012.html Third Party Advisory
https://access.redhat.com/errata/RHSA-2014:0414 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=975126 Issue Tracking Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16887 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19565 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19582 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:jdk:1.6.0:update22:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update23:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update24:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update25:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update26:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update27:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update29:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update30:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update31:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update32:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update33:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update34:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update35:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update37:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update38:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update39:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update41:*:*:*:*:*:*
cpe:2.3:a:oracle:jdk:1.6.0:update43:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_10:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_11:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_12:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_13:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_14:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_15:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_16:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_17:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_18:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_19:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_20:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_21:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_3:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_4:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_5:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_6:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update_7:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update1:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update1_b06:*:*:*:*:*:*
cpe:2.3:a:sun:jdk:1.6.0:update2:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:oracle:jre:1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update1:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update10:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update11:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update13:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update15:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update17:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update2:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update3:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update4:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update5:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update6:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update7:*:*:*:*:*:*
cpe:2.3:a:oracle:jre:1.7.0:update9:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:oracle:jrockit:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:jrockit:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:openjdk:1.7.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:51

Type Values Removed Values Added
References () http://advisories.mageia.org/MGASA-2013-0185.html - Third Party Advisory () http://advisories.mageia.org/MGASA-2013-0185.html - Third Party Advisory
References () http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/abe9ea5a50d2 - Third Party Advisory () http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/abe9ea5a50d2 - Third Party Advisory
References () http://marc.info/?l=bugtraq&m=137545505800971&w=2 - Mailing List, Third Party Advisory () http://marc.info/?l=bugtraq&m=137545505800971&w=2 - Mailing List, Third Party Advisory
References () http://marc.info/?l=bugtraq&m=137545592101387&w=2 - Mailing List, Third Party Advisory () http://marc.info/?l=bugtraq&m=137545592101387&w=2 - Mailing List, Third Party Advisory
References () http://rhn.redhat.com/errata/RHSA-2013-0963.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2013-0963.html - Third Party Advisory
References () http://seclists.org/fulldisclosure/2014/Dec/23 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2014/Dec/23 - Mailing List, Third Party Advisory
References () http://secunia.com/advisories/54154 - Third Party Advisory () http://secunia.com/advisories/54154 - Third Party Advisory
References () http://security.gentoo.org/glsa/glsa-201406-32.xml - Third Party Advisory () http://security.gentoo.org/glsa/glsa-201406-32.xml - Third Party Advisory
References () http://www.mandriva.com/security/advisories?name=MDVSA-2013:183 - Third Party Advisory () http://www.mandriva.com/security/advisories?name=MDVSA-2013:183 - Third Party Advisory
References () http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html - Vendor Advisory () http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html - Vendor Advisory
References () http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html - Vendor Advisory () http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html - Vendor Advisory
References () http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html - Vendor Advisory () http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html - Vendor Advisory
References () http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html - Vendor Advisory () http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html - Vendor Advisory
References () http://www.securityfocus.com/archive/1/534161/100/0/threaded - Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/534161/100/0/threaded - Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/60645 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/60645 - Third Party Advisory, VDB Entry
References () http://www.us-cert.gov/ncas/alerts/TA13-169A - Third Party Advisory, US Government Resource () http://www.us-cert.gov/ncas/alerts/TA13-169A - Third Party Advisory, US Government Resource
References () http://www.vmware.com/security/advisories/VMSA-2014-0012.html - Third Party Advisory () http://www.vmware.com/security/advisories/VMSA-2014-0012.html - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2014:0414 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2014:0414 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=975126 - Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=975126 - Issue Tracking, Third Party Advisory
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16887 - Third Party Advisory () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16887 - Third Party Advisory
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19565 - Third Party Advisory () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19565 - Third Party Advisory
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19582 - Third Party Advisory () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19582 - Third Party Advisory

Information

Published : 2013-06-18 22:55

Updated : 2024-11-21 01:51


NVD link : CVE-2013-2461

Mitre link : CVE-2013-2461

CVE.ORG link : CVE-2013-2461


JSON object : View

Products Affected

sun

  • jdk

oracle

  • jdk
  • jrockit
  • jre
  • openjdk