Upstream information

CVE-2013-0429 at MITRE

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue involves the creation of a single PresentationManager that is shared across multiple thread groups, which allows remote attackers to bypass Java sandbox restrictions.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having critical severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 7.6
Vector AV:N/AC:H/Au:N/C:C/I:C/A:C
Access Vector Network
Access Complexity High
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
SUSE Bugzilla entries: 801972 [RESOLVED / FIXED], 803379 [RESOLVED / FIXED], 806786 [RESOLVED / UPSTREAM]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 11 SP2
  • java-1_6_0-openjdk >= 1.6.0.0_b27.1.12.2-0.2.1
  • java-1_6_0-openjdk-demo >= 1.6.0.0_b27.1.12.2-0.2.1
  • java-1_6_0-openjdk-devel >= 1.6.0.0_b27.1.12.2-0.2.1
Patchnames:
sledsp2-java-1_6_0-openjdk
SUSE Linux Enterprise Desktop 12
  • java-1_7_0-openjdk >= 1.7.0.65-3.7
  • java-1_7_0-openjdk-headless >= 1.7.0.65-3.7
Patchnames:
SUSE Linux Enterprise Desktop 12 GA java-1_7_0-openjdk
SUSE Linux Enterprise Desktop 12 SP1
  • java-1_7_0-openjdk >= 1.7.0.91-21.2
  • java-1_7_0-openjdk-headless >= 1.7.0.91-21.2
Patchnames:
SUSE Linux Enterprise Desktop 12 SP1 GA java-1_7_0-openjdk
SUSE Linux Enterprise Desktop 12 SP2
  • java-1_7_0-openjdk >= 1.7.0.111-33.1
  • java-1_7_0-openjdk-headless >= 1.7.0.111-33.1
Patchnames:
SUSE Linux Enterprise Desktop 12 SP2 GA java-1_7_0-openjdk
SUSE Linux Enterprise Desktop 12 SP3
  • java-1_7_0-openjdk >= 1.7.0.141-42.1
  • java-1_7_0-openjdk-headless >= 1.7.0.141-42.1
Patchnames:
SUSE Linux Enterprise Desktop 12 SP3 GA java-1_7_0-openjdk
SUSE Linux Enterprise Server 12
  • java-1_7_0-openjdk >= 1.7.0.6-33.3
  • java-1_7_0-openjdk-demo >= 1.7.0.6-33.3
  • java-1_7_0-openjdk-devel >= 1.7.0.6-33.3
  • java-1_7_0-openjdk-headless >= 1.7.0.6-33.3
Patchnames:
SUSE Linux Enterprise Server 12 GA java-1_7_0-openjdk
SUSE Linux Enterprise Server 12 SP1
  • java-1_7_0-openjdk >= 1.7.0.91-21.2
  • java-1_7_0-openjdk-demo >= 1.7.0.91-21.2
  • java-1_7_0-openjdk-devel >= 1.7.0.91-21.2
  • java-1_7_0-openjdk-headless >= 1.7.0.91-21.2
Patchnames:
SUSE Linux Enterprise Server 12 SP1 GA java-1_7_0-openjdk
SUSE Linux Enterprise Server 12 SP2
  • java-1_7_0-openjdk >= 1.7.0.111-33.1
  • java-1_7_0-openjdk-demo >= 1.7.0.111-33.1
  • java-1_7_0-openjdk-devel >= 1.7.0.111-33.1
  • java-1_7_0-openjdk-headless >= 1.7.0.111-33.1
Patchnames:
SUSE Linux Enterprise Server 12 SP2 GA java-1_7_0-openjdk
SUSE Linux Enterprise Server 12 SP3
  • java-1_7_0-openjdk >= 1.7.0.141-42.1
  • java-1_7_0-openjdk-demo >= 1.7.0.141-42.1
  • java-1_7_0-openjdk-devel >= 1.7.0.141-42.1
  • java-1_7_0-openjdk-headless >= 1.7.0.141-42.1
Patchnames:
SUSE Linux Enterprise Server 12 SP3 GA java-1_7_0-openjdk
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
  • java-1_7_0-openjdk >= 1.7.0.111-33.1
  • java-1_7_0-openjdk-demo >= 1.7.0.111-33.1
  • java-1_7_0-openjdk-devel >= 1.7.0.111-33.1
  • java-1_7_0-openjdk-headless >= 1.7.0.111-33.1
Patchnames:
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 GA java-1_7_0-openjdk
SUSE Linux Enterprise Desktop 11 SP2
  • java-1_6_0-openjdk >= 1.6.0.0_b27.1.12.2-0.2.1
  • java-1_6_0-openjdk-demo >= 1.6.0.0_b27.1.12.2-0.2.1
  • java-1_6_0-openjdk-devel >= 1.6.0.0_b27.1.12.2-0.2.1
Builds
SAT Patch Nr: 7332
openSUSE Tumbleweed
  • java-1_7_0-openjdk >= 1.7.0.121-1.1
  • java-1_7_0-openjdk-accessibility >= 1.7.0.121-1.1
  • java-1_7_0-openjdk-bootstrap >= 1.7.0.121-1.1
  • java-1_7_0-openjdk-bootstrap-devel >= 1.7.0.121-1.1
  • java-1_7_0-openjdk-bootstrap-headless >= 1.7.0.121-1.1
  • java-1_7_0-openjdk-demo >= 1.7.0.121-1.1
  • java-1_7_0-openjdk-devel >= 1.7.0.121-1.1
  • java-1_7_0-openjdk-headless >= 1.7.0.121-1.1
  • java-1_7_0-openjdk-javadoc >= 1.7.0.121-1.1
  • java-1_7_0-openjdk-src >= 1.7.0.121-1.1
Patchnames:
openSUSE Tumbleweed GA java-1_7_0-openjdk