Upstream information
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue involves the creation of a single PresentationManager that is shared across multiple thread groups, which allows remote attackers to bypass Java sandbox restrictions.NVD CVSS v2 Base Score: 7.6 (AV:N/AC:H/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Novell Bugzilla entries: 801972, 803379, 806786 SUSE Security Advisories:- openSUSE-SU-2013:0308-1, published Tue, 19 Feb 2013 11:04:35 +0100 (CET)
- openSUSE-SU-2013:0312-1, published Tue, 19 Feb 2013 15:04:26 +0100 (CET)
- openSUSE-SU-2013:0377-1, published Fri, 1 Mar 2013 17:05:38 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SLE 11 SP2 DEBUGINFO |
| Builds SAT Patch Nr: 7332 |
| SUSE Linux Enterprise Desktop 11 SP2 |
| Builds SAT Patch Nr: 7332 |
