Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-0443

Опубликовано: 02 фев. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4

Описание

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect validation of Diffie-Hellman keys, which allows remote attackers to conduct a "small subgroup attack" to force the use of weak session keys or obtain sensitive information about the private key.

РелизСтатусПримечание
devel

released

6b27-1.12.1-2ubuntu2
hardy

released

6b27-1.12.3-0ubuntu1~08.04.1
lucid

released

6b27-1.12.1-2ubuntu0.10.04.2
oneiric

released

6b27-1.12.1-2ubuntu0.11.10.2
precise

released

6b27-1.12.1-2ubuntu0.12.04.2
quantal

released

6b27-1.12.1-2ubuntu0.12.10.2
upstream

pending

6b24-1.11.6, 6b27-1.12.1

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

DNE

lucid

ignored

end of life
oneiric

ignored

end of life
precise

DNE

quantal

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

released

7u13-2.3.6-1ubuntu1
hardy

DNE

lucid

DNE

oneiric

released

7u13-2.3.6-0ubuntu0.11.10.2
precise

released

7u13-2.3.6-0ubuntu0.12.04.1
quantal

released

7u13-2.3.6-0ubuntu0.12.10.1
upstream

pending

7u9-2.3.5

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

ignored

end of life
lucid

DNE

oneiric

DNE

precise

DNE

quantal

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

ignored

end of life
lucid

DNE

removed from archive
oneiric

DNE

precise

DNE

quantal

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 64%
0.00468
Низкий

4 Medium

CVSS2

Связанные уязвимости

redhat
больше 12 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect validation of Diffie-Hellman keys, which allows remote attackers to conduct a "small subgroup attack" to force the use of weak session keys or obtain sensitive information about the private key.

nvd
больше 12 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect validation of Diffie-Hellman keys, which allows remote attackers to conduct a "small subgroup attack" to force the use of weak session keys or obtain sensitive information about the private key.

debian
больше 12 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) compon ...

github
больше 3 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect validation of Diffie-Hellman keys, which allows remote attackers to conduct a "small subgroup attack" to force the use of weak session keys or obtain sensitive information about the private key.

oracle-oval
больше 12 лет назад

ELSA-2013-0246: java-1.6.0-openjdk security update (IMPORTANT)

EPSS

Процентиль: 64%
0.00468
Низкий

4 Medium

CVSS2