PT-2013-3795 · Oracle+4 · Oracle Jrockit+7

Stefan Cornelius

·

Published

2013-06-18

·

Updated

2024-06-15

·

CVE-2013-2461

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Java SE versions prior to 7 Update 21 Java SE versions prior to 6 Update 45 Oracle JRockit versions prior to R27.7.5 Oracle JRockit versions prior to R28.2.7 OpenJDK 7
Description The issue affects confidentiality, integrity, and availability. It is related to Libraries and may allow remote attackers to bypass verification of XML signatures via vectors related to a missing check for a valid DOMCanonicalizationMethod canonicalization algorithm.
Recommendations For Java SE versions prior to 7 Update 21, update to a version later than 7 Update 21. For Java SE versions prior to 6 Update 45, update to a version later than 6 Update 45. For Oracle JRockit versions prior to R27.7.5, update to a version later than R27.7.5. For Oracle JRockit versions prior to R28.2.7, update to a version later than R28.2.7. For OpenJDK 7, update to a version later than OpenJDK 7.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CESA-2013_0957
CESA-2013_1014
CVE-2013-2461
DSA-2722-1
DSA-2727-1
HPSBUX02907
HPSBUX02908
MGASA-2013-0185
MGASA-2013-0208
OPENSUSE-SU-2024:10534-1
RHSA-2013:0957
RHSA-2013:0958
RHSA-2013:0963
RHSA-2013:1014
RHSA-2013_0957
RHSA-2013_0958
RHSA-2013_0963
RHSA-2013_1014
RHSA-2014:0414
RHSA-2014_0414

Affected Products

Centos
Hp-Ux
Java Platform
Java Se
Openjdk
Oracle Jrockit
Red Hat
Suse