Novell Home

CVE-2013-0431

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2013-0431 at MITRE

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.

NVD CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N)

Novell/SUSE information

Note from the SUSE Security Team

This security problem affects also IBM Java on SUSE Linux Enterprise Server in various versions.

IBM is still working on a fix currently. As soon as a fix is provided we will be shipping updated IBM Java packages.

Please check the IBM JDK Alerts overview page for more information and the current IBM status.

Novell Bugzilla entries: 798535, 803379, 806786

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Software Development Kit 11 SP2
  • java-1_7_0-ibm-devel >= 1.7.0_sr4.0-0.6.1
Builds
SAT Patch Nr: 7454
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Server 11 SP2 for VMware
  • java-1_7_0-ibm >= 1.7.0_sr4.0-0.6.1
  • java-1_7_0-ibm-alsa >= 1.7.0_sr4.0-0.6.1
  • java-1_7_0-ibm-jdbc >= 1.7.0_sr4.0-0.6.1
  • java-1_7_0-ibm-plugin >= 1.7.0_sr4.0-0.6.1
Builds
SAT Patch Nr: 7454
SUSE Linux Enterprise Server 11 SP2
  • java-1_7_0-ibm >= 1.7.0_sr4.0-0.6.1
  • java-1_7_0-ibm-jdbc >= 1.7.0_sr4.0-0.6.1
Builds
SAT Patch Nr: 7454
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Server 11 SP2 for VMware
  • java-1_7_0-ibm >= 1.7.0_sr4.0-0.6.1
  • java-1_7_0-ibm-jdbc >= 1.7.0_sr4.0-0.6.1
  • java-1_7_0-ibm-plugin >= 1.7.0_sr4.0-0.6.1
Builds
SAT Patch Nr: 7454

© 2014 Novell