Bug 975137 (CVE-2013-2443)
| Summary: | CVE-2013-2443 OpenJDK: AccessControlContext check order issue (Libraries, 8001330) | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Stefan Cornelius <scorneli> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | dbhole, jlieskov, jvanek, security-response-team |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2013-07-17 16:22:09 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 973111 | ||
|
Comment 1
Jan Lieskovsky
2013-06-19 13:34:06 UTC
Common Vulnerabilities and Exposures assigned CVE identifier of CVE-2013-2443 to the following vulnerability: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality via unknown vectors related to Libraries, a different vulnerability than CVE-2013-2452 and CVE-2013-2455. Upstream commits: http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/f6dce3552285 http://hg.openjdk.java.net/jdk7u/jdk7u/hotspot/rev/0344da726f70 This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2013:0958 https://rhn.redhat.com/errata/RHSA-2013-0958.html This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2013:0957 https://rhn.redhat.com/errata/RHSA-2013-0957.html This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 5 Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2013:0963 https://rhn.redhat.com/errata/RHSA-2013-0963.html This issue has been addressed in following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Via RHSA-2013:1014 https://rhn.redhat.com/errata/RHSA-2013-1014.html This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 5 Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2013:1059 https://rhn.redhat.com/errata/RHSA-2013-1059.html This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 6 Supplementary for Red Hat Enterprise Linux 5 Via RHSA-2013:1081 https://rhn.redhat.com/errata/RHSA-2013-1081.html Fixed in IcedTea6 versions 1.11.12 and 1.12.6, and IcedTea7 versions 2.3.10 and 2.4.1: http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-July/023941.html http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-June/023849.html http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-July/023895.html This issue has been addressed in following products: Red Hat Network Satellite Server v 5.5 Via RHSA-2013:1456 https://rhn.redhat.com/errata/RHSA-2013-1456.html This issue has been addressed in following products: Red Hat Network Satellite Server v 5.4 Via RHSA-2013:1455 https://rhn.redhat.com/errata/RHSA-2013-1455.html This issue has been addressed in following products: Oracle Java for Red Hat Enterprise Linux 6 Oracle Java for Red Hat Enterprise Linux 5 Via RHSA-2014:0414 https://rhn.redhat.com/errata/RHSA-2014-0414.html |