Описание
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via vectors related to RMI. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to cross-site scripting (XSS) in the sun.rmi.transport.proxy CGIHandler class that does not properly handle error messages in a (1) command or (2) port number.
Релиз | Статус | Примечание |
---|---|---|
devel | released | 6b27-1.12.1-2ubuntu2 |
hardy | released | 6b27-1.12.3-0ubuntu1~08.04.1 |
lucid | released | 6b27-1.12.1-2ubuntu0.10.04.2 |
oneiric | released | 6b27-1.12.1-2ubuntu0.11.10.2 |
precise | released | 6b27-1.12.1-2ubuntu0.12.04.2 |
quantal | released | 6b27-1.12.1-2ubuntu0.12.10.2 |
upstream | pending | 6b24-1.11.6, 6b27-1.12.1 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | DNE | |
lucid | ignored | end of life |
oneiric | ignored | end of life |
precise | DNE | |
quantal | DNE | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | released | 7u13-2.3.6-1ubuntu1 |
hardy | DNE | |
lucid | DNE | |
oneiric | released | 7u13-2.3.6-0ubuntu0.11.10.2 |
precise | released | 7u13-2.3.6-0ubuntu0.12.04.1 |
quantal | released | 7u13-2.3.6-0ubuntu0.12.10.1 |
upstream | pending | 7u9-2.3.5 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | ignored | end of life |
lucid | DNE | |
oneiric | DNE | |
precise | DNE | |
quantal | DNE | |
upstream | ignored | end of life |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | ignored | end of life |
lucid | DNE | removed from archive |
oneiric | DNE | |
precise | DNE | |
quantal | DNE | |
upstream | needs-triage |
Показывать по
Ссылки на источники
EPSS
5 Medium
CVSS2
Связанные уязвимости
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via vectors related to RMI. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to cross-site scripting (XSS) in the sun.rmi.transport.proxy CGIHandler class that does not properly handle error messages in a (1) command or (2) port number.
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via vectors related to RMI. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to cross-site scripting (XSS) in the sun.rmi.transport.proxy CGIHandler class that does not properly handle error messages in a (1) command or (2) port number.
Unspecified vulnerability in the Java Runtime Environment (JRE) compon ...
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via vectors related to RMI. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to cross-site scripting (XSS) in the sun.rmi.transport.proxy CGIHandler class that does not properly handle error messages in a (1) command or (2) port number.
ELSA-2013-0246: java-1.6.0-openjdk security update (IMPORTANT)
EPSS
5 Medium
CVSS2