FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-0433

This CVE name corresponds to:

Entered Topic
2013-01-14 java 7.x -- security manager bypass

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-0433
Phase Assigned(20121207)

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect integrity via unknown vectors related to Networking. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to avoid triggering an exception during the deserialization of invalid InetSocketAddress data.

References

Source Reference
CONFIRM http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
CONFIRM http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS
CONFIRM http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ab011765c4e8
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=907456
REDHAT RHSA-2013:0236
REDHAT RHSA-2013:0237
REDHAT RHSA-2013:0245
REDHAT RHSA-2013:0246
REDHAT RHSA-2013:0247
SUSE openSUSE-SU-2013:0312
SUSE openSUSE-SU-2013:0377
CERT TA13-032A
CERT-VN VU#858729