CVE-2013-1569
Published: 17 April 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "checking of [a] glyph table" in the International Components for Unicode (ICU) Layout Engine before 51.2.
Notes
Author | Note |
---|---|
mdeslaur | in lucid+, NetX and the plugin moved to the icedtea-web package |
jdstrand | sun-java6 is not redistributable, no longer in the archive and no longer tracked sun-java5 is EOL upstream and no longer tracked as of 2013-04-19, IcedTea has not released 2.3.9 or 1.12.5 to fix this issue |
Priority
Status
Package | Release | Status |
---|---|---|
icedtea-web Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Not vulnerable
|
|
oneiric |
Not vulnerable
|
|
precise |
Not vulnerable
|
|
quantal |
Not vulnerable
|
|
raring |
Not vulnerable
|
|
trusty |
Does not exist
(trusty was not-affected)
|
|
upstream |
Not vulnerable
|
|
utopic |
Not vulnerable
|
|
icu Launchpad, Ubuntu, Debian |
lucid |
Ignored
(end of life)
|
precise |
Released
(4.8.1.1-3ubuntu0.3)
|
|
trusty |
Not vulnerable
(52.1-3)
|
|
upstream |
Released
(51.2)
|
|
utopic |
Not vulnerable
(52.1-6)
|
|
Patches: upstream: http://bugs.icu-project.org/trac/changeset/33535 (trunk) upstream: http://bugs.icu-project.org/trac/changeset/33537 (51.1.1) upstream: http://bugs.icu-project.org/trac/changeset/33538 (docs) upstream: http://bugs.icu-project.org/trac/changeset/33540 (api doc) upstream: http://bugs.icu-project.org/trac/changeset/33712 (mem leak) upstream: http://download.icu-project.org/files/icu4c/51.1/icu-51-layout-fix-10107.tgz |
||
openjdk-6 Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Released
(6b27-1.12.5-0ubuntu0.10.04.1)
|
|
oneiric |
Released
(6b27-1.12.5-0ubuntu0.11.10.1)
|
|
precise |
Released
(6b27-1.12.5-0ubuntu0.12.04.1)
|
|
quantal |
Released
(6b27-1.12.5-0ubuntu0.12.10.1)
|
|
raring |
Released
(6b27-1.12.5-1ubuntu1)
|
|
trusty |
Does not exist
(trusty was not-affected)
|
|
upstream |
Released
(6u45)
|
|
utopic |
Not vulnerable
|
|
openjdk-6b18 Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Ignored
(end of life)
|
|
oneiric |
Ignored
(end of life)
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
utopic |
Does not exist
|
|
openjdk-7 Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Does not exist
|
|
oneiric |
Released
(7u21-2.3.9-0ubuntu0.11.10.1)
|
|
precise |
Released
(7u21-2.3.9-0ubuntu0.12.04.1)
|
|
quantal |
Released
(7u21-2.3.9-0ubuntu0.12.10.1)
|
|
raring |
Released
(7u21-2.3.9-1ubuntu1)
|
|
trusty |
Does not exist
(trusty was not-affected)
|
|
upstream |
Released
(7u21)
|
|
utopic |
Not vulnerable
|
|
Patches: upstream: http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/6784c9903db7 |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1569
- http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html
- https://ubuntu.com/security/notices/USN-1806-1
- https://ubuntu.com/security/notices/USN-1819-1
- http://site.icu-project.org/download/51#TOC-Known-Issues
- https://ubuntu.com/security/notices/USN-2522-1
- NVD
- Launchpad
- Debian