PT-2013-3795 · Oracle+4 · Oracle Jrockit+7

Stefan Cornelius

·

Publicado

2013-06-18

·

Atualizado

2024-06-15

·

CVE-2013-2461

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Java SE versions prior to 7 Update 21 Java SE versions prior to 6 Update 45 Oracle JRockit versions prior to R27.7.5 Oracle JRockit versions prior to R28.2.7 OpenJDK 7
Description The issue affects confidentiality, integrity, and availability. It is related to Libraries and may allow remote attackers to bypass verification of XML signatures via vectors related to a missing check for a valid DOMCanonicalizationMethod canonicalization algorithm.
Recommendations For Java SE versions prior to 7 Update 21, update to a version later than 7 Update 21. For Java SE versions prior to 6 Update 45, update to a version later than 6 Update 45. For Oracle JRockit versions prior to R27.7.5, update to a version later than R27.7.5. For Oracle JRockit versions prior to R28.2.7, update to a version later than R28.2.7. For OpenJDK 7, update to a version later than OpenJDK 7.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CESA-2013_0957
CESA-2013_1014
CVE-2013-2461
DSA-2722-1
DSA-2727-1
HPSBUX02907
HPSBUX02908
MGASA-2013-0185
MGASA-2013-0208
OPENSUSE-SU-2024:10534-1
RHSA-2013:0957
RHSA-2013:0958
RHSA-2013:0963
RHSA-2013:1014
RHSA-2013_0957
RHSA-2013_0958
RHSA-2013_0963
RHSA-2013_1014
RHSA-2014:0414
RHSA-2014_0414

Produtos afetados

Centos
Hp-Ux
Java Platform
Java Se
Openjdk
Oracle Jrockit
Red Hat
Suse