CVE-2013-5820
published 2013-10-16CVE-2013-5820: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect…
PriorityP430medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
4.17%
89.8th percentile
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect integrity via vectors related to JAX-WS.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | <= 1.7.0 | — |
| oracle | jdk | <= 1.6.0 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | <= 1.6.0 | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_ubuntu6.4MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2014-01-23·CVSS 6.4
CVE-2013-5817 [MEDIUM] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,
CVE-2013-5804, CVE-2014-0411)
Several vulnerabilities were discovered in the OpenJDK JRE related to
availability. An attacker could exploit these to cause a denial of service.
(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825, CVE-2013-5896,
CVE-2013-5910)
Several vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,
CVE-2013-5820, CVE-2014-0376, CVE-2014-0416)
Several vulnerabilities we
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2013-11-21·CVSS 6.4
CVE-2013-3829 [MEDIUM] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2013-3829, CVE-2013-5783,
CVE-2013-5804)
Several vulnerabilities were discovered in the OpenJDK JRE related to
availability. An attacker could exploit these to cause a denial of service.
(CVE-2013-4002, CVE-2013-5803, CVE-2013-5823, CVE-2013-5825)
Several vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2013-5772, CVE-2013-5774, CVE-2013-5784, CVE-2013-5797,
CVE-2013-5820)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An atta
Red Hat
OpenJDK: insufficient security checks (JAXWS, 8017505)
vendor_redhat·2013-10-15·CVSS 5.0
CVE-2013-5820 [MEDIUM] OpenJDK: insufficient security checks (JAXWS, 8017505)
OpenJDK: insufficient security checks (JAXWS, 8017505)
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect integrity via vectors related to JAX-WS.
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-7phw-hfv6-72h3: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers
ghsa_unreviewed·2022-05-14
CVE-2013-5820 [MEDIUM] GHSA-7phw-hfv6-72h3: Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect integrity via vectors related to JAX-WS.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6411 openttd: DoS using forcefully crashed aircrafts
bugzilla·2013-11-29·CVSS 5.0
CVE-2013-6411 [MEDIUM] CVE-2013-6411 openttd: DoS using forcefully crashed aircrafts
CVE-2013-6411 openttd: DoS using forcefully crashed aircrafts
OpenTTD, a transportation business simulation game, is found to have a missing validation that allows remote attackers to cause a denial of service (crash) by forcefully crashing aircraft near the corner of the map. This triggers a corner case where data outside of the allocated map array is accessed.
The issue is said to be fixed in OpenTTD 1.3.3.
References:
http://seclists.org/oss-sec/2013/q4/372
http://bugs.openttd.org/task/5820
Discussion:
Created openttd tracking bugs for this issue:
Affects: fedora-all [bug 1035992]
---
openttd-1.3.3-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
---
openttd-1.3.3-1.fc19 has been pushed to the Fedo
Bugzilla
CVE-2013-5820 OpenJDK: insufficient security checks (JAXWS, 8017505)
bugzilla·2013-10-14·CVSS 5.0
CVE-2013-5820 [MEDIUM] CVE-2013-5820 OpenJDK: insufficient security checks (JAXWS, 8017505)
CVE-2013-5820 OpenJDK: insufficient security checks (JAXWS, 8017505)
It was discovered that the JAXWS component of OpenJDK failed to perform security checks properly. An untrusted Java application or applet could possibly use this flaw to bypass certain Java sandbox restrictions because of insufficient checks when invoking object methods, or because of insufficient object type checks.
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html
---
Fixed in Oracle Java SE 7u45 and 6u65.
OpenJDK upstream commit:
http://hg.openjdk.java.net/jdk7u/jdk7u/jaxws/rev/76e34b113c91
---
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 6
Supplementary for Red Hat Enterprise Linux 5
Via RHSA-2013:14
http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00023.htmlhttp://marc.info/?l=bugtraq&m=138674031212883&w=2http://marc.info/?l=bugtraq&m=138674073720143&w=2http://rhn.redhat.com/errata/RHSA-2013-1440.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1447.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1451.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1505.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1507.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1508.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1793.htmlhttp://secunia.com/advisories/56338http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://support.apple.com/kb/HT5982http://www-01.ibm.com/support/docview.wss?uid=swg21655201http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS13-025/index.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.htmlhttp://www.securityfocus.com/bid/63133http://www.ubuntu.com/usn/USN-2033-1http://www.ubuntu.com/usn/USN-2089-1https://access.redhat.com/errata/RHSA-2014:0414https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19206http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00023.htmlhttp://marc.info/?l=bugtraq&m=138674031212883&w=2http://marc.info/?l=bugtraq&m=138674073720143&w=2http://rhn.redhat.com/errata/RHSA-2013-1440.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1447.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1451.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1505.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1507.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1508.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1793.htmlhttp://secunia.com/advisories/56338http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://support.apple.com/kb/HT5982http://www-01.ibm.com/support/docview.wss?uid=swg21655201http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS13-025/index.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.htmlhttp://www.securityfocus.com/bid/63133http://www.ubuntu.com/usn/USN-2033-1http://www.ubuntu.com/usn/USN-2089-1https://access.redhat.com/errata/RHSA-2014:0414https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19206
2013-10-16
Published