Novell Home

CVE-2013-2445

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2013-2445 at MITRE

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect availability via unknown vectors related to Hotspot. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "handling of memory allocation errors."

NVD CVSS v2 Base Score: 7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C)

Novell/SUSE information

Novell Bugzilla entries: 825624, 828665, 829708

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 11 SP2
  • java-1_6_0-openjdk >= 1.6.0.0_b27.1.12.6-0.2.1
  • java-1_6_0-openjdk-demo >= 1.6.0.0_b27.1.12.6-0.2.1
  • java-1_6_0-openjdk-devel >= 1.6.0.0_b27.1.12.6-0.2.1
Builds
SAT Patch Nr: 8084
SUSE Linux Enterprise Desktop 11 SP3
  • java-1_7_0-openjdk >= 1.7.0.6-0.19.2
  • java-1_7_0-openjdk-demo >= 1.7.0.6-0.19.2
  • java-1_7_0-openjdk-devel >= 1.7.0.6-0.19.2
Builds
SAT Patch Nr: 8090

© 2014 Novell