PT-2013-1525 · Oracle+3 · Java Se+4

Published

2013-02-01

·

Updated

2022-05-13

·

CVE-2012-1541

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 6 through Update 38 Oracle Java SE versions 7 through Update 11
Description The issue affects confidentiality, integrity, and availability via unknown vectors related to Deployment. It is reportedly different from other vulnerabilities listed in the February 2013 CPU. There are claims from a third party that the issue may be due to an interaction error between the JRE plug-in for WebKit-based browsers and the Javascript engine, potentially allowing remote attackers to execute arbitrary code by modifying DOM nodes that contain applet elements.
Recommendations For Oracle Java SE versions 6 through Update 38, update to a version later than Update 38 to resolve the issue. For Oracle Java SE versions 7 through Update 11, update to a version later than Update 11 to resolve the issue. As a temporary workaround, consider restricting the use of the JRE plug-in for WebKit-based browsers until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2012-1541
HPSBUX02857
HPSBUX02864
RHSA-2013:0236
RHSA-2013:0237
RHSA-2013:0625
RHSA-2013:0626
RHSA-2013:1455
RHSA-2013:1456
RHSA-2013_0236
RHSA-2013_0237
RHSA-2013_0625
RHSA-2013_0626

Affected Products

Hp-Ux
Java Platform
Java Se
Red Hat
Suse