OpenJDK: Hotspot MethodHandle lookup error (Hotspot, 8009699)
Published Apr 17, 2013
9.3
HIGHCVSS 2.0
EPSS 5.69%
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect MethodHandle lookups, which allows remote attackers to bypass Java sandbox restrictions.
Affected products
No data.
Configuration 1
- ≤ 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
Configuration 2
- ≤ 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
No data.
Red Hat Enterprise Linux 5
java-1.6.0-openjdk-1:1.6.0.0-1.40.1.11.11.el5_9
Fixed · RHSA-2013:0770
Red Hat Enterprise Linux 5
java-1.7.0-openjdk-1:1.7.0.19-2.3.9.1.el5_9
Fixed · RHSA-2013:0752
Red Hat Enterprise Linux 6
java-1.6.0-openjdk-1:1.6.0.0-1.61.1.11.11.el6_4
Fixed · RHSA-2013:0770
Red Hat Enterprise Linux 6
java-1.7.0-openjdk-1:1.7.0.19-2.3.9.1.el6_4
Fixed · RHSA-2013:0751
Supplementary for Red Hat Enterprise Linux 5
java-1.7.0-oracle-1:1.7.0.21-1jpp.1.el5
Fixed · RHSA-2013:0757
Supplementary for Red Hat Enterprise Linux 6
java-1.7.0-oracle-1:1.7.0.21-1jpp.1.el6
Fixed · RHSA-2013:0757
Red Hat Enterprise Linux 5
java-1.6.0-sun
Not affected
Red Hat Enterprise Linux 6
java-1.6.0-sun
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | java-1.6.0-openjdk-1:1.6.0.0-1.40.1.11.11.el5_9 | Fixed | RHSA-2013:0770 |
| Red Hat Enterprise Linux 5 | java-1.7.0-openjdk-1:1.7.0.19-2.3.9.1.el5_9 | Fixed | RHSA-2013:0752 |
| Red Hat Enterprise Linux 6 | java-1.6.0-openjdk-1:1.6.0.0-1.61.1.11.11.el6_4 | Fixed | RHSA-2013:0770 |
| Red Hat Enterprise Linux 6 | java-1.7.0-openjdk-1:1.7.0.19-2.3.9.1.el6_4 | Fixed | RHSA-2013:0751 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.7.0-oracle-1:1.7.0.21-1jpp.1.el5 | Fixed | RHSA-2013:0757 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.7.0-oracle-1:1.7.0.21-1jpp.1.el6 | Fixed | RHSA-2013:0757 |
| Red Hat Enterprise Linux 5 | java-1.6.0-sun | Not affected | n/a |
| Red Hat Enterprise Linux 6 | java-1.6.0-sun | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (23)
- http://blog.fuseyism.com/index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released/ x_refsource_CONFIRM
- http://blog.fuseyism.com/index.php/2013/04/25/security-icedtea-1-11-11-1-12-5-for-openjdk-6-released/ x_refsource_CONFIRM
- http://hg.openjdk.java.net/jdk7u/jdk7u-dev/hotspot/rev/663b5c744e82 x_refsource_MISC
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00007.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-05/msg00017.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-06/msg00099.html vendor-advisoryx_refsource_SUSE
- http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022796.html mailing-listx_refsource_MLIST
- http://rhn.redhat.com/errata/RHSA-2013-0752.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2013-0757.html vendor-advisoryx_refsource_REDHAT
- http://security.gentoo.org/glsa/glsa-201406-32.xml vendor-advisoryx_refsource_GENTOO
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:145 vendor-advisoryx_refsource_MANDRIVA
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:161 vendor-advisoryx_refsource_MANDRIVA
- http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html x_refsource_CONFIRMVendor Advisory
- http://www.ubuntu.com/usn/USN-1806-1 vendor-advisoryx_refsource_UBUNTU
- http://www.us-cert.gov/ncas/alerts/TA13-107A third-party-advisoryx_refsource_CERTUS Government Resource
- https://access.redhat.com/security/cve/CVE-2013-2421 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=952649 x_refsource_MISCIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2367 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-2421
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16258 vdb-entrysignaturex_refsource_OVAL
- https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0124 x_refsource_CONFIRM
- https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0130 x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2013-2421
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data