OpenJDK: ObjectInputStream/ObjectOutputStream missing checks (Libraries, 8014987)
Published Oct 16, 2013
10.0
HIGHCVSS 2.0
EPSS 17.61%
Description
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-5850.
Affected products
No data.
Configuration 1
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.5.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.6.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
- 1.7.0
Configuration 2
- 5.0
- 6.0
- 6.4
- 5.0
- 6.0
- 6.4
- 5.0
- 6.0
Configuration 3
- 10.04
- 12.04
- 12.10
- 13.04
- 13.10
No data.
Oracle Java for Red Hat Enterprise Linux 5
java-1.6.0-sun-1:1.6.0.75-1jpp.3.el5_10
Fixed · RHSA-2014:0414
Oracle Java for Red Hat Enterprise Linux 6
java-1.6.0-sun-1:1.6.0.75-1jpp.1.el6_5
Fixed · RHSA-2014:0414
Red Hat Enterprise Linux 5
java-1.6.0-openjdk-1:1.6.0.0-1.42.1.11.14.el5_10
Fixed · RHSA-2013:1505
Red Hat Enterprise Linux 5
java-1.7.0-openjdk-1:1.7.0.45-2.4.3.1.el5_10
Fixed · RHSA-2013:1447
Red Hat Enterprise Linux 6
java-1.6.0-openjdk-1:1.6.0.0-1.65.1.11.14.el6_4
Fixed · RHSA-2013:1505
Red Hat Enterprise Linux 6
java-1.7.0-openjdk-1:1.7.0.45-2.4.3.2.el6_4
Fixed · RHSA-2013:1451
Red Hat Network Satellite Server v 5.4
java-1.6.0-ibm-1:1.6.0.15.0-1jpp.1.el5
Fixed · RHSA-2013:1793
Red Hat Network Satellite Server v 5.5
java-1.6.0-ibm-1:1.6.0.15.0-1jpp.1.el5
Fixed · RHSA-2013:1793
Red Hat Satellite 5.6
java-1.6.0-ibm-1:1.6.0.15.0-1jpp.1.el5
Fixed · RHSA-2013:1793
Supplementary for Red Hat Enterprise Linux 5
java-1.5.0-ibm-1:1.5.0.16.4-1jpp.1.el5_10
Fixed · RHSA-2013:1509
Supplementary for Red Hat Enterprise Linux 5
java-1.6.0-ibm-1:1.6.0.15.0-1jpp.1.el5_10
Fixed · RHSA-2013:1508
Supplementary for Red Hat Enterprise Linux 5
java-1.7.0-ibm-1:1.7.0.6.0-1jpp.1.el5_10
Fixed · RHSA-2013:1507
Supplementary for Red Hat Enterprise Linux 5
java-1.7.0-oracle-1:1.7.0.45-1jpp.1.el5_10
Fixed · RHSA-2013:1440
Supplementary for Red Hat Enterprise Linux 6
java-1.5.0-ibm-1:1.5.0.16.4-1jpp.1.el6_4
Fixed · RHSA-2013:1509
Supplementary for Red Hat Enterprise Linux 6
java-1.6.0-ibm-1:1.6.0.15.0-1jpp.1.el6_4
Fixed · RHSA-2013:1508
Supplementary for Red Hat Enterprise Linux 6
java-1.7.0-ibm-1:1.7.0.6.0-1jpp.1.el6_4
Fixed · RHSA-2013:1507
Supplementary for Red Hat Enterprise Linux 6
java-1.7.0-oracle-1:1.7.0.45-1jpp.2.el6_4
Fixed · RHSA-2013:1440
| Product | Package | State | Advisory |
|---|---|---|---|
| Oracle Java for Red Hat Enterprise Linux 5 | java-1.6.0-sun-1:1.6.0.75-1jpp.3.el5_10 | Fixed | RHSA-2014:0414 |
| Oracle Java for Red Hat Enterprise Linux 6 | java-1.6.0-sun-1:1.6.0.75-1jpp.1.el6_5 | Fixed | RHSA-2014:0414 |
| Red Hat Enterprise Linux 5 | java-1.6.0-openjdk-1:1.6.0.0-1.42.1.11.14.el5_10 | Fixed | RHSA-2013:1505 |
| Red Hat Enterprise Linux 5 | java-1.7.0-openjdk-1:1.7.0.45-2.4.3.1.el5_10 | Fixed | RHSA-2013:1447 |
| Red Hat Enterprise Linux 6 | java-1.6.0-openjdk-1:1.6.0.0-1.65.1.11.14.el6_4 | Fixed | RHSA-2013:1505 |
| Red Hat Enterprise Linux 6 | java-1.7.0-openjdk-1:1.7.0.45-2.4.3.2.el6_4 | Fixed | RHSA-2013:1451 |
| Red Hat Network Satellite Server v 5.4 | java-1.6.0-ibm-1:1.6.0.15.0-1jpp.1.el5 | Fixed | RHSA-2013:1793 |
| Red Hat Network Satellite Server v 5.5 | java-1.6.0-ibm-1:1.6.0.15.0-1jpp.1.el5 | Fixed | RHSA-2013:1793 |
| Red Hat Satellite 5.6 | java-1.6.0-ibm-1:1.6.0.15.0-1jpp.1.el5 | Fixed | RHSA-2013:1793 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.5.0-ibm-1:1.5.0.16.4-1jpp.1.el5_10 | Fixed | RHSA-2013:1509 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.6.0-ibm-1:1.6.0.15.0-1jpp.1.el5_10 | Fixed | RHSA-2013:1508 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.7.0-ibm-1:1.7.0.6.0-1jpp.1.el5_10 | Fixed | RHSA-2013:1507 |
| Supplementary for Red Hat Enterprise Linux 5 | java-1.7.0-oracle-1:1.7.0.45-1jpp.1.el5_10 | Fixed | RHSA-2013:1440 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.5.0-ibm-1:1.5.0.16.4-1jpp.1.el6_4 | Fixed | RHSA-2013:1509 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.6.0-ibm-1:1.6.0.15.0-1jpp.1.el6_4 | Fixed | RHSA-2013:1508 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.7.0-ibm-1:1.7.0.6.0-1jpp.1.el6_4 | Fixed | RHSA-2013:1507 |
| Supplementary for Red Hat Enterprise Linux 6 | java-1.7.0-oracle-1:1.7.0.45-1jpp.2.el6_4 | Fixed | RHSA-2013:1440 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (31)
- http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html vendor-advisoryx_refsource_APPLEMailing List
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00010.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00013.html vendor-advisoryx_refsource_SUSEBroken Link
- http://lists.opensuse.org/opensuse-updates/2013-11/msg00023.html vendor-advisoryx_refsource_SUSEBroken Link
- http://marc.info/?l=bugtraq&m=138674031212883&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=138674073720143&w=2 vendor-advisoryx_refsource_HPIssue TrackingMailing ListThird Party Advisory
- http://osvdb.org/98532 vdb-entryx_refsource_OSVDBBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-1440.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1447.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1451.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1505.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1507.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1508.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1509.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1793.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://secunia.com/advisories/56338 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://security.gentoo.org/glsa/glsa-201406-32.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://support.apple.com/kb/HT5982 x_refsource_CONFIRMThird Party Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21655201 x_refsource_CONFIRMThird Party Advisory
- http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS13-025/index.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/63150 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-2033-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2089-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-13-246/ x_refsource_MISCThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2014:0414 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2013-5842 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1019123 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-5842
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18436 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cve.org/CVERecord?id=CVE-2013-5842
Change history (0)
No recorded changes yet.