JDK: unspecified vulnerability fixed in 7u21 and 6u45 (2D)
Published Apr 17, 2013
10.0
HIGHCVSS 2.0
EPSS 7.13%
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2394 and CVE-2013-1491.
Affected products
No data.
Configuration 1
- ≤ 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
Configuration 2
- ≤ 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
Configuration 3
- ≤ 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
Configuration 4
- ≤ 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
Configuration 5
- ≤ 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
Configuration 6
- ≤ 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
Configuration 7
No data.
Red Hat Network Satellite Server v 5.4
java-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el5_9
Fixed · RHSA-2013:1455
Red Hat Network Satellite Server v 5.5
java-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el5_9
Fixed · RHSA-2013:1456
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-ibm-1:1.5.0.16.2-1jpp.1.el5_9
Fixed · RHSA-2013:0855
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-ibm-1:1.6.0.13.2-1jpp.1.el5_9
Fixed · RHSA-2013:0823
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.45-1jpp.1.el5_9
Fixed · RHSA-2013:0758
Supplementary for Red Hat Enterprise Linux 5
java-1.7.0-ibm-1:1.7.0.4.2-1jpp.1.el5_9
Fixed · RHSA-2013:0822
Supplementary for Red Hat Enterprise Linux 5
java-1.7.0-oracle-1:1.7.0.21-1jpp.1.el5
Fixed · RHSA-2013:0757
Supplementary for Red Hat Enterprise Linux 6
java-1.5.0-ibm-1:1.5.0.16.2-1jpp.1.el6_4
Fixed · RHSA-2013:0855
Supplementary for Red Hat Enterprise Linux 6
java-1.6.0-ibm-1:1.6.0.13.2-1jpp.1.el6_4
Fixed · RHSA-2013:0823
Supplementary for Red Hat Enterprise Linux 6
java-1.6.0-sun-1:1.6.0.45-1jpp.1.el6
Fixed · RHSA-2013:0758
Supplementary for Red Hat Enterprise Linux 6
java-1.7.0-ibm-1:1.7.0.4.2-1jpp.1.el6_4
Fixed · RHSA-2013:0822
Supplementary for Red Hat Enterprise Linux 6
java-1.7.0-oracle-1:1.7.0.21-1jpp.1.el6
Fixed · RHSA-2013:0757
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Network Satellite Server v 5.4 | java-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el5_9 | Fixed | RHSA-2013:1455 |
| Red Hat Network Satellite Server v 5.5 | java-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el5_9 | Fixed | RHSA-2013:1456 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-ibm-1:1.5.0.16.2-1jpp.1.el5_9 | Fixed | RHSA-2013:0855 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-ibm-1:1.6.0.13.2-1jpp.1.el5_9 | Fixed | RHSA-2013:0823 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.45-1jpp.1.el5_9 | Fixed | RHSA-2013:0758 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.7.0-ibm-1:1.7.0.4.2-1jpp.1.el5_9 | Fixed | RHSA-2013:0822 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.7.0-oracle-1:1.7.0.21-1jpp.1.el5 | Fixed | RHSA-2013:0757 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.5.0-ibm-1:1.5.0.16.2-1jpp.1.el6_4 | Fixed | RHSA-2013:0855 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.6.0-ibm-1:1.6.0.13.2-1jpp.1.el6_4 | Fixed | RHSA-2013:0823 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.6.0-sun-1:1.6.0.45-1jpp.1.el6 | Fixed | RHSA-2013:0758 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.7.0-ibm-1:1.7.0.4.2-1jpp.1.el6_4 | Fixed | RHSA-2013:0822 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.7.0-oracle-1:1.7.0.21-1jpp.1.el6 | Fixed | RHSA-2013:0757 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (21)
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880 vendor-advisoryx_refsource_HP
- http://lists.apple.com/archives/security-announce/2013/Apr/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00013.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00001.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00007.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=137283787217316&w=2 vendor-advisoryx_refsource_HP
- http://rhn.redhat.com/errata/RHSA-2013-0757.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2013-0758.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2013-1455.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2013-1456.html vendor-advisoryx_refsource_REDHAT
- http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/59154 vdb-entryx_refsource_BID
- http://www.us-cert.gov/ncas/alerts/TA13-107A third-party-advisoryx_refsource_CERTUS Government Resource
- https://access.redhat.com/security/cve/CVE-2013-2432 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=953269 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2378 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-2432
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16611 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18850 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18914 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2013-2432
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data