CVE-2013-0425
published 2013-02-02CVE-2013-0425: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38…
PriorityP355critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
8.09%
94.2th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0428 and CVE-2013-0426. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "access control checks" in the logging API that allow remote attackers to bypass Java sandbox restrictions.
Affected
87 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | <= 1.4.2_40 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | <= 1.4.2_40 | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2013-02-14·CVSS 10.0
CVE-2012-1541 [CRITICAL] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Several security issues were fixed in OpenJDK.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,
CVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,
CVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,
CVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,
CVE-2013-1478, CVE-2013-1480)
Vulnerabilities were discovered in the OpenJDK JRE related to information
disclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)
Several data integrity vulnerabilities were discovered in the OpenJDK JRE.
(CVE-2013-0424, CVE-2013-0
Red Hat
OpenJDK: reflection API incorrect checks for proxy classes (Libraries, 7197546, SE-2012-01 Issue 29)
vendor_redhat·2013-02-01·CVSS 10.0
CVE-2013-0428 [CRITICAL] OpenJDK: reflection API incorrect checks for proxy classes (Libraries, 7197546, SE-2012-01 Issue 29)
OpenJDK: reflection API incorrect checks for proxy classes (Libraries, 7197546, SE-2012-01 Issue 29)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0425 and CVE-2013-0426. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "incorrect checks for proxy classes" in the Reflection API.
Package: java-1.4.2-ibm (Red Hat Enterprise Linux 5) - Will not fix
Red Hat
OpenJDK: logging insufficient access control checks (Libraries, 6664528)
vendor_redhat·2013-02-01·CVSS 10.0
CVE-2013-0426 [CRITICAL] OpenJDK: logging insufficient access control checks (Libraries, 6664528)
OpenJDK: logging insufficient access control checks (Libraries, 6664528)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0425 and CVE-2013-0428. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "access control checks" in the logging API that allow remote attackers to bypass Java sandbox restrictions.
Package: java-1.4.2-ibm (Red Hat Enterprise Linux 5) - Will not fix
Red Hat
OpenJDK: logging insufficient access control checks (Libraries, 6664509)
vendor_redhat·2013-02-01·CVSS 10.0
CVE-2013-0425 [CRITICAL] OpenJDK: logging insufficient access control checks (Libraries, 6664509)
OpenJDK: logging insufficient access control checks (Libraries, 6664509)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0428 and CVE-2013-0426. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "access control checks" in the logging API that allow remote attackers to bypass Java sandbox restrictions.
Package: java-1.4.2-ibm (Red Hat Enterprise Linux 5) - Will not fix
GHSA
GHSA-2c2g-g7mc-jv23: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5
ghsa_unreviewed·2022-05-05·CVSS 10.0
CVE-2013-0426 [CRITICAL] GHSA-2c2g-g7mc-jv23: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0425 and CVE-2013-0428. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "access control checks" in the logging API that allow remote attackers to bypass Java sandbox restrictions.
GHSA
GHSA-58g3-37cc-r74w: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5
ghsa_unreviewed·2022-05-05·CVSS 10.0
CVE-2013-0425 [CRITICAL] GHSA-58g3-37cc-r74w: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0428 and CVE-2013-0426. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "access control checks" in the logging API that allow remote attackers to bypass Java sandbox restrictions.
GHSA
GHSA-r97x-9xgg-cf5w: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5
ghsa_unreviewed·2022-05-05·CVSS 10.0
CVE-2013-0428 [CRITICAL] GHSA-r97x-9xgg-cf5w: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-0425 and CVE-2013-0426. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "incorrect checks for proxy classes" in the Reflection API.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0425 OpenJDK: logging insufficient access control checks (Libraries, 6664509)
bugzilla·2013-02-04·CVSS 10.0
CVE-2013-0425 [CRITICAL] CVE-2013-0425 OpenJDK: logging insufficient access control checks (Libraries, 6664509)
CVE-2013-0425 OpenJDK: logging insufficient access control checks (Libraries, 6664509)
It was discovered that Java logging API does not properly perform access control checks. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
Upstream commit, as included in IcedTea7 repositories:
http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ce105dd2e4de
(Includes fixes for both CVE-2013-0425 (bug 907344) and CVE-2013-0426 (bug 907346)).
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.
Bugzilla
CVE-2013-0426 OpenJDK: logging insufficient access control checks (Libraries, 6664528)
bugzilla·2013-02-04·CVSS 10.0
CVE-2013-0426 [CRITICAL] CVE-2013-0426 OpenJDK: logging insufficient access control checks (Libraries, 6664528)
CVE-2013-0426 OpenJDK: logging insufficient access control checks (Libraries, 6664528)
It was discovered that Java logging API does not properly perform access control checks. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Discussion:
Upstream commit, as included in IcedTea7 repositories:
http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ce105dd2e4de
(Includes fixes for both CVE-2013-0425 (bug 907344) and CVE-2013-0426 (bug 907346)).
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2013:0237 https://rhn.redhat.
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907344http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWShttp://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ce105dd2e4dehttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.htmlhttp://marc.info/?l=bugtraq&m=136439120408139&w=2http://marc.info/?l=bugtraq&m=136570436423916&w=2http://marc.info/?l=bugtraq&m=136733161405818&w=2http://rhn.redhat.com/errata/RHSA-2013-0236.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0237.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0245.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0246.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0247.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.kb.cert.org/vuls/id/858729http://www.mandriva.com/security/advisories?name=MDVSA-2013:095http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.htmlhttp://www.securityfocus.com/bid/57709http://www.us-cert.gov/cas/techalerts/TA13-032A.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16058https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19483https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19502https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19503https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=907344http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWShttp://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/ce105dd2e4dehttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.htmlhttp://marc.info/?l=bugtraq&m=136439120408139&w=2http://marc.info/?l=bugtraq&m=136570436423916&w=2http://marc.info/?l=bugtraq&m=136733161405818&w=2http://rhn.redhat.com/errata/RHSA-2013-0236.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0237.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0245.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0246.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0247.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.kb.cert.org/vuls/id/858729http://www.mandriva.com/security/advisories?name=MDVSA-2013:095http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.htmlhttp://www.securityfocus.com/bid/57709http://www.us-cert.gov/cas/techalerts/TA13-032A.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16058https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19483https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19502https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19503https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056
2013-02-02
Published