CVE-2013-1569
Published: 17 April 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "checking of [a] glyph table" in the International Components for Unicode (ICU) Layout Engine before 51.2.
Priority
Status
Package | Release | Status |
---|---|---|
icedtea-web Launchpad, Ubuntu, Debian |
Upstream |
Not vulnerable
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
(trusty was not-affected)
|
|
icu Launchpad, Ubuntu, Debian |
Upstream |
Released
(51.2)
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Not vulnerable
(52.1-3)
|
|
Patches: Upstream: http://bugs.icu-project.org/trac/changeset/33535 (trunk) Upstream: http://bugs.icu-project.org/trac/changeset/33537 (51.1.1) Upstream: http://bugs.icu-project.org/trac/changeset/33538 (docs) Upstream: http://bugs.icu-project.org/trac/changeset/33540 (api doc) Upstream: http://bugs.icu-project.org/trac/changeset/33712 (mem leak) Upstream: http://download.icu-project.org/files/icu4c/51.1/icu-51-layout-fix-10107.tgz |
||
openjdk-6 Launchpad, Ubuntu, Debian |
Upstream |
Released
(6u45)
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
(trusty was not-affected)
|
|
openjdk-6b18 Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
|
openjdk-7 Launchpad, Ubuntu, Debian |
Upstream |
Released
(7u21)
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
(trusty was not-affected)
|
|
Patches: Upstream: http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/6784c9903db7 |
Notes
Author | Note |
---|---|
mdeslaur | in lucid+, NetX and the plugin moved to the icedtea-web package |
jdstrand | sun-java6 is not redistributable, no longer in the archive and no longer tracked sun-java5 is EOL upstream and no longer tracked as of 2013-04-19, IcedTea has not released 2.3.9 or 1.12.5 to fix this issue |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1569
- http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html
- https://usn.ubuntu.com/usn/usn-1806-1
- https://usn.ubuntu.com/usn/usn-1819-1
- http://site.icu-project.org/download/51#TOC-Known-Issues
- https://usn.ubuntu.com/usn/usn-2522-1
- NVD
- Launchpad
- Debian