CVE-2013-0424
Publication date 1 February 2013
Last updated 24 July 2024
Ubuntu priority
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via vectors related to RMI. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to cross-site scripting (XSS) in the sun.rmi.transport.proxy CGIHandler class that does not properly handle error messages in a (1) command or (2) port number.
Status
Package | Ubuntu Release | Status |
---|---|---|
openjdk-6 | ||
openjdk-6b18 | ||
openjdk-7 | ||
sun-java5 | ||
sun-java6 | ||
References
Related Ubuntu Security Notices (USN)
- USN-1724-1
- OpenJDK vulnerabilities
- 14 February 2013