Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-1488

Опубликовано: 16 апр. 2013
Источник: redhat
CVSS2: 6.8

Описание

The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString calls," and the JDBC driver manager, as demonstrated by James Forshaw during a Pwn2Own competition at CanSecWest 2013.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5java-1.6.0-sunNot affected
Red Hat Enterprise Linux 6java-1.6.0-sunNot affected
Red Hat Enterprise Linux 5java-1.7.0-openjdkFixedRHSA-2013:075217.04.2013
Red Hat Enterprise Linux 5java-1.6.0-openjdkFixedRHSA-2013:077024.04.2013
Red Hat Enterprise Linux 6java-1.7.0-openjdkFixedRHSA-2013:075117.04.2013
Red Hat Enterprise Linux 6java-1.6.0-openjdkFixedRHSA-2013:077024.04.2013
Supplementary for Red Hat Enterprise Linux 5java-1.7.0-oracleFixedRHSA-2013:075718.04.2013
Supplementary for Red Hat Enterprise Linux 5java-1.7.0-ibmFixedRHSA-2013:082214.05.2013
Supplementary for Red Hat Enterprise Linux 6java-1.7.0-oracleFixedRHSA-2013:075718.04.2013
Supplementary for Red Hat Enterprise Linux 6java-1.7.0-ibmFixedRHSA-2013:082214.05.2013

Показывать по

Дополнительная информация

Статус:

Critical
https://bugzilla.redhat.com/show_bug.cgi?id=920247OpenJDK: JDBC driver manager improper toString calls (CanSecWest 2013, Libraries, 8009814)

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString calls," and the JDBC driver manager, as demonstrated by James Forshaw during a Pwn2Own competition at CanSecWest 2013.

nvd
больше 12 лет назад

The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString calls," and the JDBC driver manager, as demonstrated by James Forshaw during a Pwn2Own competition at CanSecWest 2013.

debian
больше 12 лет назад

The Java Runtime Environment (JRE) component in Oracle Java SE 7 Updat ...

github
больше 3 лет назад

The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString calls," and the JDBC driver manager, as demonstrated by James Forshaw during a Pwn2Own competition at CanSecWest 2013.

oracle-oval
больше 12 лет назад

ELSA-2013-0770: java-1.6.0-openjdk security update (IMPORTANT)

6.8 Medium

CVSS2