{"cves":[{"id":"CVE-2013-1478","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through\nUpdate 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote\nattackers to affect confidentiality, integrity, and availability via\nunknown vectors related to 2D. NOTE: the previous information is from the\nFebruary 2013 CPU. Oracle has not commented on claims from another vendor\nthat this issue is related to \"insufficient validation of raster\nparameters\" that can trigger an integer overflow and memory corruption.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-1478"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-1476","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through\nUpdate 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote\nattackers to affect confidentiality, integrity, and availability via\nvectors related to CORBA, a different vulnerability than CVE-2013-0441 and\nCVE-2013-1475. NOTE: the previous information is from the February 2013\nCPU. Oracle has not commented on claims from another vendor that this issue\nallows remote attackers to bypass Java sandbox restrictions via \"certain\nvalue handler constructors.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-1476"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-1475","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through\nUpdate 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote\nattackers to affect confidentiality, integrity, and availability via\nvectors related to CORBA. NOTE: the previous information is from the\nFebruary 2013 CPU. Oracle has not commented on claims from another vendor\nthat this issue is related to \"IIOP type reuse management\" in\nObjectStreamClass.java.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-1475"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-1473","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote\nattackers to affect integrity via unknown vectors related to Deployment.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-1473"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0450","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through\nUpdate 38, and OpenJDK 6 and 7, allows remote attackers to affect\nconfidentiality, integrity, and availability via vectors related to JMX.\nNOTE: the previous information is from the February 2013 CPU. Oracle has\nnot commented on claims from another vendor that this issue is related to\nimproper checks of \"access control context\" in the JMX RequiredModelMBean\nclass.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0450"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0449","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11 allows remote attackers to affect\nconfidentiality via unknown vectors related to Deployment.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0449"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0448","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11 allows remote attackers to affect\nintegrity via unknown vectors related to Libraries.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"http://rhn.redhat.com/errata/RHSA-2013-0237.html states this is\nOracle JDK only, but based on Oracle advisory we claimed it was fixed in\nhttps://ubuntu.com/security/notices/USN-1724-1."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0448"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0446","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote\nattackers to affect confidentiality, integrity, and availability via\nunknown vectors related to Deployment, a different vulnerability than other\nCVEs listed in the February 2013 CPU.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0446"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0445","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through\nUpdate 38, and OpenJDK 6 and 7, allows remote attackers to affect\nconfidentiality, integrity, and availability via vectors related to AWT.\nNOTE: the previous information is from the February 2013 CPU. Oracle has\nnot commented on claims from another vendor that this issue is related to\nan improper check of \"privileges of the code\" that bypasses the sandbox.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0445"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0444","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11, and OpenJDK 7, allows remote\nattackers to affect confidentiality, integrity, and availability via\nunknown vectors related to Beans. NOTE: the previous information is from\nthe February 2013 CPU. Oracle has not commented on claims from another\nvendor that this issue is related to \"insufficient checks for cached\nresults\" by the Java Beans MethodFinder, which might allow attackers to\naccess methods that should only be accessible to privileged code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0444"],"bugs":[""],"patches":{},"tags":{},"packages":[{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0443","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through\nUpdate 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote\nattackers to affect confidentiality and integrity via vectors related to\nJSSE. NOTE: the previous information is from the February 2013 CPU. Oracle\nhas not commented on claims from another vendor that this issue is related\nto incorrect validation of Diffie-Hellman keys, which allows remote\nattackers to conduct a \"small subgroup attack\" to force the use of weak\nsession keys or obtain sensitive information about the private key.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0443"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0442","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through\nUpdate 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote\nattackers to affect confidentiality, integrity, and availability via\nvectors related to AWT. NOTE: the previous information is from the\nFebruary 2013 CPU. Oracle has not commented on claims from another vendor\nthat this issue is related to an improper check of \"privileges of the code\"\nthat bypasses the sandbox.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0442"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0441","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through\nUpdate 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote\nattackers to affect confidentiality, integrity, and availability via\nvectors related to CORBA, a different vulnerability than CVE-2013-1476 and\nCVE-2013-1475. NOTE: the previous information is from the February 2013\nCPU. Oracle has not commented on claims from another vendor that this issue\nallows remote attackers to bypass Java sandbox restrictions via certain\nmethods that should not be serialized, aka \"missing serialization\nrestriction.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0441"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0440","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through\nUpdate 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers\nto affect availability via vectors related to JSSE. NOTE: the previous\ninformation is from the February 2013 CPU. Oracle has not commented on\nclaims from another vendor that this issue is related to CPU consumption in\nthe SSL/TLS implementation via a large number of ClientHello packets that\nare not properly handled by (1) ClientHandshaker.java and (2)\nServerHandshaker.java.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0440"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0438","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote\nattackers to affect confidentiality via unknown vectors related to\nDeployment.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0438"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0435","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11 and 6 through Update 38, and OpenJDK\n6 and 7, allows remote attackers to affect confidentiality via vectors\nrelated to JAX-WS. NOTE: the previous information is from the February\n2013 CPU. Oracle has not commented on claims from another vendor that this\nissue is related to improper restriction of com.sun.xml.internal packages\nand \"Better handling of UI elements.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0435"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0434","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through\nUpdate 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote\nattackers to affect confidentiality via vectors related to JAXP. NOTE: the\nprevious information is from the February 2013 CPU. Oracle has not\ncommented on claims from another vendor that this issue is related to the\npublic declaration of the loadPropertyFile method in the JAXP\nFuncSystemProperty class, which allows remote attackers to obtain sensitive\ninformation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0434"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0433","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through\nUpdate 38, and OpenJDK 6 and 7, allows remote attackers to affect integrity\nvia unknown vectors related to Networking. NOTE: the previous information\nis from the February 2013 CPU. Oracle has not commented on claims from\nanother vendor that this issue allows remote attackers to avoid triggering\nan exception during the deserialization of invalid InetSocketAddress data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0433"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0432","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through\nUpdate 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote\nattackers to affect confidentiality and integrity via vectors related to\nAWT. NOTE: the previous information is from the February 2013 CPU. Oracle\nhas not commented on claims from another vendor that this issue is related\nto \"insufficient clipboard access premission checks.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0432"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]},{"id":"CVE-2013-0430","published":"2013-02-01T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in the Java Runtime Environment (JRE) component\nin Oracle Java SE 7 through Update 11 and 6 through Update 38, allows local\nusers to affect confidentiality, integrity, and availability via unknown\nvectors related to the installation process of the client.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html","http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html","https://ubuntu.com/security/notices/USN-1724-1","https://www.cve.org/CVERecord?id=CVE-2013-0430"],"bugs":[""],"patches":{"sun-java6":[],"sun-java5":[],"openjdk-6":[],"openjdk-6b18":[]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"hardy","status":"released","description":"6b27-1.12.3-0ubuntu1~08.04.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"released","description":"6b27-1.12.1-2ubuntu0.10.04.2","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"6b27-1.12.1-2ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"6b27-1.12.1-2ubuntu0.12.04.2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"6b27-1.12.1-2ubuntu0.12.10.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"6b24-1.11.6, 6b27-1.12.1","component":null,"pocket":"security"}]},{"name":"openjdk-6b18","source":"https://ubuntu.com/security/cve?package=openjdk-6b18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6b18","debian":"https://tracker.debian.org/pkg/openjdk-6b18","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"7u13-2.3.6-0ubuntu0.11.10.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"7u13-2.3.6-0ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"7u13-2.3.6-0ubuntu0.12.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"7u9-2.3.5","component":null,"pocket":"security"}]},{"name":"sun-java5","source":"https://ubuntu.com/security/cve?package=sun-java5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java5","debian":"https://tracker.debian.org/pkg/sun-java5","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"sun-java6","source":"https://ubuntu.com/security/cve?package=sun-java6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sun-java6","debian":"https://tracker.debian.org/pkg/sun-java6","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"removed from archive","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-1724-1"],"notices":[{"id":"USN-1724-1","title":"OpenJDK vulnerabilities","summary":"Several security issues were fixed in OpenJDK.\n","instructions":"This update uses a new upstream release which includes additional bug\nfixes. After a standard system update you need to restart any Java\napplications or applets to make all the necessary changes.\n","references":[],"published":"2013-02-14T22:00:18.836393","description":"Several vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. An attacker could exploit these\nto cause a denial of service. (CVE-2012-1541, CVE-2012-3342, CVE-2013-0351,\nCVE-2013-0419, CVE-2013-0423, CVE-2013-0446, CVE-2012-3213, CVE-2013-0425,\nCVE-2013-0426, CVE-2013-0428, CVE-2013-0429, CVE-2013-0430, CVE-2013-0441,\nCVE-2013-0442, CVE-2013-0445, CVE-2013-0450, CVE-2013-1475, CVE-2013-1476,\nCVE-2013-1478, CVE-2013-1480)\n\nVulnerabilities were discovered in the OpenJDK JRE related to information\ndisclosure. (CVE-2013-0409, CVE-2013-0434, CVE-2013-0438)\n\nSeveral data integrity vulnerabilities were discovered in the OpenJDK JRE.\n(CVE-2013-0424, CVE-2013-0427, CVE-2013-0433, CVE-2013-1473)\n\nSeveral vulnerabilities were discovered in the OpenJDK JRE related to\ninformation disclosure and data integrity. (CVE-2013-0432, CVE-2013-0435,\nCVE-2013-0443)\n\nA vulnerability was discovered in the OpenJDK JRE related to availability.\nAn attacker could exploit this to cause a denial of service.\n(CVE-2013-0440)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue only affected Ubuntu 12.10. (CVE-2013-0444)\n\nA data integrity vulnerability was discovered in the OpenJDK JRE. This\nissue only affected Ubuntu 12.10. (CVE-2013-0448)\n\nAn information disclosure vulnerability was discovered in the OpenJDK JRE.\nThis issue only affected Ubuntu 12.10. (CVE-2013-0449)\n\nA vulnerability was discovered in the OpenJDK JRE related to information\ndisclosure and data integrity. An attacker could exploit this to cause a\ndenial of service. This issue did not affect Ubuntu 12.10. (CVE-2013-1481)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.12.04.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.12.04.2"}],"lucid":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.10.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.10.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.10.04.2"}],"quantal":[{"name":"openjdk-7","version":"7u13-2.3.6-0ubuntu0.12.10.1","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-7-jre-lib","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-zero","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"icedtea-7-jre-jamvm","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre-headless","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"},{"name":"openjdk-7-jre","version":"7u13-2.3.6-0ubuntu0.12.10.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u13-2.3.6-0ubuntu0.12.10.1"}],"oneiric":[{"name":"openjdk-6","version":"6b27-1.12.1-2ubuntu0.11.10.2","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-6-jre-cacao","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"icedtea-6-jre-jamvm","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-headless","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-zero","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"},{"name":"openjdk-6-jre-lib","version":"6b27-1.12.1-2ubuntu0.11.10.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-6","version_link":"https://launchpad.net/ubuntu/+source/openjdk-6/6b27-1.12.1-2ubuntu0.11.10.2"}]},"type":"USN","cves_ids":["CVE-2012-1541","CVE-2012-3213","CVE-2012-3342","CVE-2013-0351","CVE-2013-0409","CVE-2013-0419","CVE-2013-0423","CVE-2013-0424","CVE-2013-0425","CVE-2013-0426","CVE-2013-0427","CVE-2013-0428","CVE-2013-0429","CVE-2013-0430","CVE-2013-0432","CVE-2013-0433","CVE-2013-0434","CVE-2013-0435","CVE-2013-0438","CVE-2013-0440","CVE-2013-0441","CVE-2013-0442","CVE-2013-0443","CVE-2013-0444","CVE-2013-0445","CVE-2013-0446","CVE-2013-0448","CVE-2013-0449","CVE-2013-0450","CVE-2013-1473","CVE-2013-1475","CVE-2013-1476","CVE-2013-1478","CVE-2013-1480","CVE-2013-1481"]}]}],"offset":68140,"limit":20,"total_results":79316}