CVE-2013-2384
published 2013-04-17CVE-2013-2384: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41…
PriorityP353critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
8.78%
94.6th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2383, and CVE-2013-2420. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "font layout" in the International Components for Unicode (ICU) Layout Engine before 51.2.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | icu | < icu 52.1-1 (bookworm) | icu 52.1-1 (bookworm) |
| oracle | jdk | <= 1.7.0 | — |
| oracle | jdk | <= 1.6.0 | — |
| oracle | jdk | <= 1.5.0 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | <= 1.6.0 | — |
| oracle | jre | <= 1.5.0 | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-68qc-65jp-4m7w: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-2383 [CRITICAL] GHSA-68qc-65jp-4m7w: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2384, and CVE-2013-2420. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "handling of [a] glyph table" in the International Components for Unicode (ICU) Layout Engine before 51.2.
GHSA
GHSA-4g67-62qq-2rv4: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-2384 [CRITICAL] GHSA-4g67-62qq-2rv4: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2383, and CVE-2013-2420. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "font layout" in the International Components for Unicode (ICU) Layout Engine before 51.2.
OSV
icu vulnerabilities
osv·2015-03-05·CVSS 10.0
CVE-2013-1569 [CRITICAL] icu vulnerabilities
icu vulnerabilities
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. This issue only affected
Ubuntu 12.04 LTS. (CVE-2013-1569, CVE-2013-2383, CVE-2013-2384,
CVE-2013-2419)
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. (CVE-2014-6585,
CVE-2014-6591)
It was discovered that ICU incorrectly handled memory operations when
processing regular expressions. If a
OSV
CVE-2013-2384: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5
osv·2013-04-17·CVSS 10.0
CVE-2013-2384 [CRITICAL] CVE-2013-2384: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2383, and CVE-2013-2420. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "font layout" in the International Components for Unicode (ICU) Layout Engine before 51.2.
OSV
CVE-2013-2383: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5
osv·2013-04-17·CVSS 10.0
CVE-2013-2383 [CRITICAL] CVE-2013-2383: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2384, and CVE-2013-2420. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "handling of [a] glyph table" in the International Components for Unicode (ICU) Layout Engine before 51.2.
Ubuntu
ICU vulnerabilities
vendor_ubuntu·2015-03-10·CVSS 10.0
CVE-2013-1569 [CRITICAL] ICU vulnerabilities
Title: ICU vulnerabilities
Summary: ICU could be made to crash or run programs as your login if it processed
specially crafted data.
USN-2522-1 fixed vulnerabilities in ICU. On Ubuntu 12.04 LTS, the font
patches caused a regression when using LibreOffice Calc. The patches have
now been updated to fix the regression.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. This issue only affected
Ubuntu 12.04 LTS. (CVE-2013-1569, CVE-2013-2383, CVE-2013-2384,
CVE-2013-2419)
It was discovered that ICU incorrectly ha
Ubuntu
ICU regression
vendor_ubuntu·2015-03-06·CVSS 10.0
[CRITICAL] ICU regression
Title: ICU regression
Summary: USN-2522-1 introduced a regression in ICU.
USN-2522-1 fixed vulnerabilities in ICU. On Ubuntu 12.04 LTS, the font
patches caused a regression when using LibreOffice Calc. The patches have
been temporarily backed out until the regression is investigated.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. This issue only affected
Ubuntu 12.04 LTS. (CVE-2013-1569, CVE-2013-2383, CVE-2013-2384,
CVE-2013-2419)
It was discovered that ICU incorrectly handled memory operations when
proc
Ubuntu
ICU vulnerabilities
vendor_ubuntu·2015-03-05·CVSS 10.0
CVE-2013-1569 [CRITICAL] ICU vulnerabilities
Title: ICU vulnerabilities
Summary: ICU could be made to crash or run programs as your login if it processed
specially crafted data.
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. This issue only affected
Ubuntu 12.04 LTS. (CVE-2013-1569, CVE-2013-2383, CVE-2013-2384,
CVE-2013-2419)
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. (CVE-2014-6585,
CVE-2014
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2013-05-07·CVSS 10.0
CVE-2013-0401 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Ben Murphy discovered a vulnerability in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit this
to execute arbitrary code. (CVE-2013-0401)
James Forshaw discovered a vulnerability in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit this to execute arbitrary code. (CVE-2013-1488)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2013-1518, CVE-2013-1537, CVE-2013-1557, CVE-2013-1558,
CVE-2013-1569, CVE-2013-23
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2013-04-23·CVSS 10.0
CVE-2013-0401 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Ben Murphy discovered a vulnerability in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit this
to execute arbitrary code. (CVE-2013-0401)
James Forshaw discovered a vulnerability in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit this to execute arbitrary code. (CVE-2013-1488)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2013-1518, CVE-2013-1537, CVE-2013-1557, CVE-2013-1569,
CVE-2013-2383, CVE-2013-23
Red Hat
ICU: Layout Engine font layout and glyph table errors (JDK 2D, 8004987)
vendor_redhat·2013-04-16·CVSS 10.0
CVE-2013-2384 [CRITICAL] ICU: Layout Engine font layout and glyph table errors (JDK 2D, 8004987)
ICU: Layout Engine font layout and glyph table errors (JDK 2D, 8004987)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2383, and CVE-2013-2420. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "font layout" in the International Components for Unicode (ICU) Layout Engine before 51.2.
Package: icu (Red Hat Directory Server 8) - Will not fix
Package: icu (Red Hat Enterprise Linux 5) - W
Red Hat
ICU: Layout Engine font layout and glyph table errors (JDK 2D, 8004986)
vendor_redhat·2013-04-16·CVSS 10.0
CVE-2013-2383 [CRITICAL] ICU: Layout Engine font layout and glyph table errors (JDK 2D, 8004986)
ICU: Layout Engine font layout and glyph table errors (JDK 2D, 8004986)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2384, and CVE-2013-2420. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "handling of [a] glyph table" in the International Components for Unicode (ICU) Layout Engine before 51.2.
Package: icu (Red Hat Directory Server 8) - Will not fix
Package: icu (Red Hat Enterpr
Debian
CVE-2013-2384: icu - Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...
vendor_debian·2013·CVSS 10.0
CVE-2013-2384 [CRITICAL] CVE-2013-2384: icu - Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2383, and CVE-2013-2420. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "font layout" in the International Components for Unicode (ICU) Layout Engine before 51.2.
Scope: local
bookworm: resolved (fixed in 52.1-1)
bullseye: resolved (fixed in 52.1-1)
forky: resolved (fixed in 52.1-1)
sid: resolved (fixed in 52.1-1)
trixie: resolved (fixed
Debian
CVE-2013-2383: icu - Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...
vendor_debian·2013·CVSS 10.0
CVE-2013-2383 [CRITICAL] CVE-2013-2383: icu - Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora...
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-1569, CVE-2013-2384, and CVE-2013-2420. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "handling of [a] glyph table" in the International Components for Unicode (ICU) Layout Engine before 51.2.
Scope: local
bookworm: resolved (fixed in 52.1-1)
bullseye: resolved (fixed in 52.1-1)
forky: resolved (fixed in 52.1-1)
sid: resolved (fixed in 52.1-1)
trixie:
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0469 ICU: layout engine glyphStorage off-by-one (OpenJDK 2D, 8067699)
bugzilla·2015-04-10·CVSS 10.0
CVE-2015-0469 [CRITICAL] CVE-2015-0469 ICU: layout engine glyphStorage off-by-one (OpenJDK 2D, 8067699)
CVE-2015-0469 ICU: layout engine glyphStorage off-by-one (OpenJDK 2D, 8067699)
An off-by-one error, leading to heap-based buffer overflow in the ICU Layout Engine ligature substitution processor. A check which was added as part of fix for CVE-2013-1569 (bug 952711) / CVE-2013-2383 (bug 952708) / CVE-2013-2384 (bug 952709) was found to contain an incorrect array boundary check. A specially crafted file could cause an application using ICU to parse untrusted font files to crash or, possibly, execute arbitrary code.
The original fix was added to OpenJDK and ICU via the following commits:
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/6784c9903db7
http://bugs.icu-project.org/trac/changeset/33535
http://bugs.icu-project.org/trac/ticket/10107
ICU code is embedded the 2D component in Ope
Bugzilla
CVE-2013-2419 CVE-2013-2383 CVE-2013-2384 CVE-2013-1569 mingw-icu various flaws [fedora-all]
bugzilla·2013-05-23·CVSS 10.0
CVE-2013-2419 [CRITICAL] CVE-2013-2419 CVE-2013-2383 CVE-2013-2384 CVE-2013-1569 mingw-icu various flaws [fedora-all]
CVE-2013-2419 CVE-2013-2383 CVE-2013-2384 CVE-2013-1569 mingw-icu various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note:
Bugzilla
CVE-2013-2419 CVE-2013-2383 CVE-2013-2384 CVE-2013-1569 icu various flaws [fedora-all]
bugzilla·2013-05-22·CVSS 10.0
CVE-2013-2419 [CRITICAL] CVE-2013-2419 CVE-2013-2383 CVE-2013-2384 CVE-2013-1569 icu various flaws [fedora-all]
CVE-2013-2419 CVE-2013-2383 CVE-2013-2384 CVE-2013-1569 icu various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this
Bugzilla
CVE-2013-2384 ICU: Layout Engine font layout and glyph table errors (JDK 2D, 8004987)
bugzilla·2013-04-16·CVSS 10.0
CVE-2013-2384 [CRITICAL] CVE-2013-2384 ICU: Layout Engine font layout and glyph table errors (JDK 2D, 8004987)
CVE-2013-2384 ICU: Layout Engine font layout and glyph table errors (JDK 2D, 8004987)
It was discovered that the 2D component contained multiple errors within the font layout and font glyph table processing. An untrusted Java application or applet could possibly use these flaws to bypass Java sandbox restrictions.
As the provided patch combined fixes for CVE-2013-2383, CVE-2013-2384 and CVE-2013-1569, it is currently not possible to match individual issues to their respective CVE identifier.
Discussion:
Public now via Oracle Java SE CPU April 2014:
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html
Fixed in 7u21 and 6u45.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0752 https://rhn.redhat.com/errata/R
Bugzilla
CVE-2013-2383 ICU: Layout Engine font layout and glyph table errors (JDK 2D, 8004986)
bugzilla·2013-04-16·CVSS 10.0
CVE-2013-2383 [CRITICAL] CVE-2013-2383 ICU: Layout Engine font layout and glyph table errors (JDK 2D, 8004986)
CVE-2013-2383 ICU: Layout Engine font layout and glyph table errors (JDK 2D, 8004986)
It was discovered that the 2D component contained multiple errors within the font layout and font glyph table processing. An untrusted Java application or applet could possibly use these flaws to bypass Java sandbox restrictions.
As the provided patch combined fixes for CVE-2013-2383, CVE-2013-2384 and CVE-2013-1569, it is currently not possible to match individual issues to their respective CVE identifier.
Discussion:
Public now via Oracle Java SE CPU April 2014:
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html
Fixed in 7u21 and 6u45.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0752 https://rhn.redhat.com/errata/R
Bugzilla
CVE-2013-1569 ICU: Layout Engine font layout and glyph table errors (JDK 2D, 8004994)
bugzilla·2013-04-16·CVSS 10.0
CVE-2013-1569 [CRITICAL] CVE-2013-1569 ICU: Layout Engine font layout and glyph table errors (JDK 2D, 8004994)
CVE-2013-1569 ICU: Layout Engine font layout and glyph table errors (JDK 2D, 8004994)
It was discovered that the 2D component contained multiple errors within the font layout and font glyph table processing. An untrusted Java application or applet could possibly use these flaws to bypass Java sandbox restrictions.
As the provided patch combined fixes for CVE-2013-2383, CVE-2013-2384 and CVE-2013-1569, it is currently not possible to match individual issues to their respective CVE identifier.
Discussion:
Public now via Oracle Java SE CPU April 2014:
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html
Fixed in 7u21 and 6u45.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0752 https://rhn.redhat.com/errata/R
http://blog.fuseyism.com/index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released/http://blog.fuseyism.com/index.php/2013/04/25/security-icedtea-1-11-11-1-12-5-for-openjdk-6-released/http://bugs.icu-project.org/trac/ticket/10107http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/6784c9903db7http://lists.apple.com/archives/security-announce/2013/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00017.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00099.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022796.htmlhttp://marc.info/?l=bugtraq&m=137283787217316&w=2http://rhn.redhat.com/errata/RHSA-2013-0752.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0757.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0758.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://site.icu-project.org/download/51#TOC-Known-Issueshttp://www.mandriva.com/security/advisories?name=MDVSA-2013:145http://www.mandriva.com/security/advisories?name=MDVSA-2013:161http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.htmlhttp://www.securityfocus.com/bid/59179http://www.ubuntu.com/usn/USN-1806-1http://www.us-cert.gov/ncas/alerts/TA13-107Ahttps://bugzilla.redhat.com/show_bug.cgi?id=952709https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16549https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19341https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19549https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0124https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0130http://blog.fuseyism.com/index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released/http://blog.fuseyism.com/index.php/2013/04/25/security-icedtea-1-11-11-1-12-5-for-openjdk-6-released/http://bugs.icu-project.org/trac/ticket/10107http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/6784c9903db7http://lists.apple.com/archives/security-announce/2013/Apr/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00007.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00007.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00017.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00099.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022796.htmlhttp://marc.info/?l=bugtraq&m=137283787217316&w=2http://rhn.redhat.com/errata/RHSA-2013-0752.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0757.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0758.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://site.icu-project.org/download/51#TOC-Known-Issueshttp://www.mandriva.com/security/advisories?name=MDVSA-2013:145http://www.mandriva.com/security/advisories?name=MDVSA-2013:161http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.htmlhttp://www.securityfocus.com/bid/59179http://www.ubuntu.com/usn/USN-1806-1http://www.us-cert.gov/ncas/alerts/TA13-107Ahttps://bugzilla.redhat.com/show_bug.cgi?id=952709https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16549https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19341https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19549https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0124https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0130
2013-04-17
Published