CVE-2013-1490 Affecting openjdk-6 package, versions <6b27-1.12.5-0ubuntu0.12.10.1


Severity

Recommended
0.0
medium
0
10

Based on Ubuntu security rating.

Threat Intelligence

EPSS
0.33% (71st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU1210-OPENJDK6-399558
  • published31 Jan 2013
  • disclosed31 Jan 2013

Introduced: 31 Jan 2013

CVE-2013-1490  (opens in a new tab)

How to fix?

Upgrade Ubuntu:12.10 openjdk-6 to version 6b27-1.12.5-0ubuntu0.12.10.1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream openjdk-6 package and not the openjdk-6 package as distributed by Ubuntu. See How to fix? for Ubuntu:12.10 relevant fixed versions and status.

Unspecified vulnerability in Oracle Java SE 7 Update 11 (JRE 1.7.0_11-b21) allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors, aka "Issue 51," a different vulnerability than CVE-2013-0431. NOTE: as of 20130130, this vulnerability does not contain any independently-verifiable details, and there is no vendor acknowledgement. A CVE identifier is being assigned because this vulnerability has received significant public attention, and the original researcher has an established history of releasing vulnerability reports that have been fixed by vendors. NOTE: this issue also exists in SE 6, but it cannot be exploited without a separate vulnerability.

CVSS Scores

version 3.1