OpenJDK: insufficient access checks in MacOS code (Swing, 8021275, 8021282)
Published Oct 16, 2013
9.3
HIGHCVSS 2.0
EPSS 3.90%
Description
Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Swing, a different vulnerability than CVE-2013-5805.
Affected products
No data.
Configuration 1
- ≤ 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
Configuration 2
- ≤ 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
No data.
Red Hat Enterprise Linux 5
java-1.5.0-ibm
Not affected
Red Hat Enterprise Linux 5
java-1.6.0-ibm
Not affected
Red Hat Enterprise Linux 5
java-1.6.0-openjdk
Not affected
Red Hat Enterprise Linux 5
java-1.7.0-ibm
Not affected
Red Hat Enterprise Linux 5
java-1.7.0-openjdk
Not affected
Red Hat Enterprise Linux 5
java-1.7.0-oracle
Not affected
Red Hat Enterprise Linux 6
java-1.5.0-ibm
Not affected
Red Hat Enterprise Linux 6
java-1.6.0-ibm
Not affected
Red Hat Enterprise Linux 6
java-1.6.0-openjdk
Not affected
Red Hat Enterprise Linux 6
java-1.7.0-ibm
Not affected
Red Hat Enterprise Linux 6
java-1.7.0-openjdk
Not affected
Red Hat Enterprise Linux 6
java-1.7.0-oracle
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | java-1.5.0-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 5 | java-1.6.0-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 5 | java-1.6.0-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 5 | java-1.7.0-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 5 | java-1.7.0-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 5 | java-1.7.0-oracle | Not affected | n/a |
| Red Hat Enterprise Linux 6 | java-1.5.0-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 6 | java-1.6.0-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 6 | java-1.6.0-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 6 | java-1.7.0-ibm | Not affected | n/a |
| Red Hat Enterprise Linux 6 | java-1.7.0-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 6 | java-1.7.0-oracle | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of Java as shipped with Red Hat Enterprise Linux 5 and 6.
No CWE recorded.
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00010.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-11/msg00023.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=138674073720143&w=2 vendor-advisoryx_refsource_HP
- http://security.gentoo.org/glsa/glsa-201406-32.xml vendor-advisoryx_refsource_GENTOO
- http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/63122 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-2089-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2013-5806 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1018761 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-5806
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18501 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2013-5806
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00010.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-updates/2013-11/msg00023.html | vendor-advisoryx_refsource_SUSE | |
| http://marc.info/?l=bugtraq&m=138674073720143&w=2 | vendor-advisoryx_refsource_HP | |
| http://security.gentoo.org/glsa/glsa-201406-32.xml | vendor-advisoryx_refsource_GENTOO | |
| http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html | x_refsource_CONFIRMVendor Advisory | |
| http://www.securityfocus.com/bid/63122 | vdb-entryx_refsource_BID | |
| http://www.ubuntu.com/usn/USN-2089-1 | vendor-advisoryx_refsource_UBUNTU | |
| https://access.redhat.com/security/cve/CVE-2013-5806 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1018761 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-5806 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18501 | vdb-entrysignaturex_refsource_OVAL | |
| https://www.cve.org/CVERecord?id=CVE-2013-5806 |
Change history (0)
No recorded changes yet.