Fedora Account System
Red Hat Associate
Red Hat Customer
It was discovered that the ObjectStreamClass class did not properly protect against circular references. An untrusted Java application or applet could possibly use this flaw to cause a denial of service.
External References: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2013:0958 https://rhn.redhat.com/errata/RHSA-2013-0958.html
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2013:0957 https://rhn.redhat.com/errata/RHSA-2013-0957.html
OpenJDK7 upstream repositories commit: http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/285765be3123
This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 5 Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2013:0963 https://rhn.redhat.com/errata/RHSA-2013-0963.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Via RHSA-2013:1014 https://rhn.redhat.com/errata/RHSA-2013-1014.html
This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 5 Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2013:1060 https://rhn.redhat.com/errata/RHSA-2013-1060.html
This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 5 Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2013:1059 https://rhn.redhat.com/errata/RHSA-2013-1059.html
This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 6 Supplementary for Red Hat Enterprise Linux 5 Via RHSA-2013:1081 https://rhn.redhat.com/errata/RHSA-2013-1081.html
Fixed in IcedTea6 versions 1.11.12 and 1.12.6, and IcedTea7 versions 2.1.9, 2.2.9, 2.3.10 and 2.4.1: http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-July/023941.html http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-June/023849.html http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-June/023860.html http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-July/023895.html
This issue has been addressed in following products: Red Hat Network Satellite Server v 5.5 Via RHSA-2013:1456 https://rhn.redhat.com/errata/RHSA-2013-1456.html
This issue has been addressed in following products: Red Hat Network Satellite Server v 5.4 Via RHSA-2013:1455 https://rhn.redhat.com/errata/RHSA-2013-1455.html
This issue has been addressed in following products: Oracle Java for Red Hat Enterprise Linux 6 Oracle Java for Red Hat Enterprise Linux 5 Via RHSA-2014:0414 https://rhn.redhat.com/errata/RHSA-2014-0414.html