PT-2013-1525 · Oracle+3 · Java Se+4
Published
2013-02-01
·
Updated
2022-05-13
·
CVE-2012-1541
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Java SE versions 6 through Update 38
Oracle Java SE versions 7 through Update 11
Description
The issue affects confidentiality, integrity, and availability via unknown vectors related to Deployment. It is reportedly different from other vulnerabilities listed in the February 2013 CPU. There are claims from a third party that the issue may be due to an interaction error between the JRE plug-in for WebKit-based browsers and the Javascript engine, potentially allowing remote attackers to execute arbitrary code by modifying DOM nodes that contain applet elements.
Recommendations
For Oracle Java SE versions 6 through Update 38, update to a version later than Update 38 to resolve the issue.
For Oracle Java SE versions 7 through Update 11, update to a version later than Update 11 to resolve the issue.
As a temporary workaround, consider restricting the use of the JRE plug-in for WebKit-based browsers until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hp-Ux
Java Platform
Java Se
Red Hat
Suse