PT-2014-2984 · Oracle+4 · Oracle Java Se Embedded+7

Publicado

2014-01-15

·

Atualizado

2024-06-15

·

CVE-2013-5893

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 7u45 Oracle Java SE Embedded versions 7u45 OpenJDK 7
Description The issue allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries. It is claimed by third parties that the issue is related to improper handling of methods in MethodHandles in HotSpot JVM, which allows attackers to escape the sandbox.
Recommendations For Oracle Java SE version 7u45, update to a version that addresses the issue. For Oracle Java SE Embedded version 7u45, update to a version that addresses the issue. For OpenJDK 7, update to a version that addresses the issue. As a temporary workaround, consider restricting access to the MethodHandles in HotSpot JVM to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CESA-2014_0026
CVE-2013-5893
HPSBUX02972
MGASA-2014-0023
OPENSUSE-SU-2024:10534-1
RHSA-2014:0026
RHSA-2014:0027
RHSA-2014:0030
RHSA-2014_0026
RHSA-2014_0027
RHSA-2014_0030

Produtos afetados

Centos
Hp-Ux
Java Platform
Openjdk
Oracle Java Se
Oracle Java Se Embedded
Red Hat
Suse