Common Vulnerabilities and Exposures assigned an identifier CVE-2013-0402 to the following vulnerability: Heap-based buffer overflow in Oracle Java 7 Update 17, and possibly other versions, allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013. References: [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0402 [2] http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157 [3] http://www.zdnet.com/pwn2own-down-go-all-the-browsers-7000012283/ [4] https://twitter.com/thezdi/status/309484730506698752
This is now fixed in Java SE 7u21 and JavaFX 2.2.21: http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html Issue is listed as affecting JavaFX component. Therefore, OpenJDK packages are not affected by this issue.
This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 5 Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2013:0757 https://rhn.redhat.com/errata/RHSA-2013-0757.html