PT-2013-3790 · Openjdk+5 · Openjdk+6
Stefan Cornelius
·
Publicado
2013-06-18
·
Atualizado
2024-06-15
·
CVE-2013-2456
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Java SE versions 7 Update 21 and earlier
Oracle Java SE versions 6 Update 45 and earlier
Oracle Java SE versions 5.0 Update 45 and earlier
OpenJDK 7
Description
The issue affects confidentiality via unknown vectors related to Serialization. It is noted that the problem might be related to improper access checks for subclasses in the ObjectOutputStream class, but this has not been confirmed by Oracle.
Recommendations
For Oracle Java SE versions 7 Update 21 and earlier, update to a version later than Update 21.
For Oracle Java SE versions 6 Update 45 and earlier, update to a version later than Update 45.
For Oracle Java SE versions 5.0 Update 45 and earlier, update to a version later than Update 45.
For OpenJDK 7, consider disabling the Serialization functionality until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Centos
Hp-Ux
Java Platform
Java Se
Openjdk
Red Hat
Suse