---
title: "CVE-2013-1490\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2013-1490?format=md
keywords: index, follow
---

# CVE-2013-1490

Publication date 31 January 2013

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Unspecified vulnerability in Oracle Java SE 7 Update 11 (JRE 1.7.0\_11-b21)
allows user-assisted remote attackers to bypass the Java security sandbox
via unspecified vectors, aka "Issue 51," a different vulnerability than
CVE-2013-0431. NOTE: as of 20130130, this vulnerability does not contain
any independently-verifiable details, and there is no vendor
acknowledgement. A CVE identifier is being assigned because this
vulnerability has received significant public attention, and the original
researcher has an established history of releasing vulnerability reports
that have been fixed by vendors. NOTE: this issue also exists in SE 6, but
it cannot be exploited without a separate vulnerability.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2013-1490?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| openjdk-6 | 13.04 raring | Fixed 6b27-1.12.5-1ubuntu1 |
| 12.10 quantal | Fixed 6b27-1.12.5-0ubuntu0.12.10.1 |
| 12.04 LTS precise | Not affected |
| 11.10 oneiric | Not affected |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Ignored end of life |
| openjdk-6b18 | 13.04 raring | Not in release |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 11.10 oneiric | Ignored end of life |
| 10.04 LTS lucid | Ignored end of life |
| 8.04 LTS hardy | Not in release |
| openjdk-7 | 13.04 raring | Not affected |
| 12.10 quantal | Not affected |
| 12.04 LTS precise | Not affected |
| 11.10 oneiric | Not affected |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |
| sun-java5 | 13.04 raring | Not in release |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Ignored end of life |
| sun-java6 | 13.04 raring | Not in release |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 11.10 oneiric | Not in release |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

in lucid+, NetX and the plugin moved to the icedtea-web package

---

### [jdstrand](https://launchpad.net/~jdstrand)

openjdk-6b18 FTBFS on 11.04 (LP: #1043003)
does not affect icedtea 2.3
as of 2013-05-07, icedtea 1.12.5 does not seem affected. Will update
pending new data

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1490)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-1490)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2013-1490)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2013-1490)

### Other references

* <http://www.informationweek.com/security/application-security/java-hacker-uncovers-two-flaws-in-latest/240146717>
* <http://seclists.org/fulldisclosure/2013/Jan/195>
* <http://seclists.org/fulldisclosure/2013/Jan/142>
* <http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53>
* <http://arstechnica.com/security/2013/01/critical-java-vulnerabilies-confirmed-in-latest-version/>
* <https://www.cve.org/CVERecord?id=CVE-2013-1490>
