It was discovered that the VersionHelper12 class did not properly honor whether or not modifyThreadGroup is restricted. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
External References: http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html
Fixed in Oracle Java SE 7u45 and 6u65. OpenJDK upstream commit: http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/600107f4664d
This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 6 Supplementary for Red Hat Enterprise Linux 5 Via RHSA-2013:1440 https://rhn.redhat.com/errata/RHSA-2013-1440.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2013:1447 https://rhn.redhat.com/errata/RHSA-2013-1447.html
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2013:1451 https://rhn.redhat.com/errata/RHSA-2013-1451.html
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Via RHSA-2013:1505 https://rhn.redhat.com/errata/RHSA-2013-1505.html
This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 6 Supplementary for Red Hat Enterprise Linux 5 Via RHSA-2013:1509 https://rhn.redhat.com/errata/RHSA-2013-1509.html
This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 5 Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2013:1508 https://rhn.redhat.com/errata/RHSA-2013-1508.html
This issue has been addressed in following products: Supplementary for Red Hat Enterprise Linux 5 Supplementary for Red Hat Enterprise Linux 6 Via RHSA-2013:1507 https://rhn.redhat.com/errata/RHSA-2013-1507.html
This issue has been addressed in following products: Red Hat Network Satellite Server v 5.4 Red Hat Network Satellite Server v 5.5 Red Hat Satellite Server v 5.6 Via RHSA-2013:1793 https://rhn.redhat.com/errata/RHSA-2013-1793.html
Fixed in IcedTea7 2.4.3 and IcedTea6 1.11.14 and 1.12.7: http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-October/025087.html http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-November/025278.html http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-November/025328.html
This issue has been addressed in following products: Oracle Java for Red Hat Enterprise Linux 6 Oracle Java for Red Hat Enterprise Linux 5 Via RHSA-2014:0414 https://rhn.redhat.com/errata/RHSA-2014-0414.html