CVE-2013-2422
Published: 17 April 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper method-invocation restrictions by the MethodUtil trampoline class, which allows remote attackers to bypass the Java sandbox.
Notes
Author | Note |
---|---|
mdeslaur | in lucid+, NetX and the plugin moved to the icedtea-web package |
jdstrand | sun-java6 is not redistributable, no longer in the archive and no longer tracked sun-java5 is EOL upstream and no longer tracked as of 2013-04-19, IcedTea has not released 2.3.9 or 1.12.5 to fix this issue |
Priority
Status
Package | Release | Status |
---|---|---|
icedtea-web Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Not vulnerable
|
|
oneiric |
Not vulnerable
|
|
precise |
Not vulnerable
|
|
quantal |
Not vulnerable
|
|
raring |
Not vulnerable
|
|
upstream |
Not vulnerable
|
|
openjdk-6 Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Released
(6b27-1.12.5-0ubuntu0.10.04.1)
|
|
oneiric |
Released
(6b27-1.12.5-0ubuntu0.11.10.1)
|
|
precise |
Released
(6b27-1.12.5-0ubuntu0.12.04.1)
|
|
quantal |
Released
(6b27-1.12.5-0ubuntu0.12.10.1)
|
|
raring |
Released
(6b27-1.12.5-1ubuntu1)
|
|
upstream |
Released
(6u45)
|
|
openjdk-6b18 Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Ignored
(end of life)
|
|
oneiric |
Ignored
(end of life)
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
upstream |
Needs triage
|
|
openjdk-7 Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Does not exist
|
|
oneiric |
Released
(7u21-2.3.9-0ubuntu0.11.10.1)
|
|
precise |
Released
(7u21-2.3.9-0ubuntu0.12.04.1)
|
|
quantal |
Released
(7u21-2.3.9-0ubuntu0.12.10.1)
|
|
raring |
Released
(7u21-2.3.9-1ubuntu1)
|
|
upstream |
Released
(7u21)
|