Oval Definition:oval:com.redhat.rhsa:def:20130602
Revision Date:2013-03-06Version:636
Title:RHSA-2013:0602: java-1.7.0-openjdk security update (Critical)
Description:These packages provide the OpenJDK 7 Java Runtime Environment and the OpenJDK 7 Software Development Kit.

  • An integer overflow flaw was found in the way the 2D component handled certain sample model instances. A specially-crafted sample model instance could cause Java Virtual Machine memory corruption and, possibly, lead to arbitrary code execution with virtual machine privileges. (CVE-2013-0809)

  • It was discovered that the 2D component did not properly reject certain malformed images. Specially-crafted raster parameters could cause Java Virtual Machine memory corruption and, possibly, lead to arbitrary code execution with virtual machine privileges. (CVE-2013-1493)

    Note: If the web browser plug-in provided by the icedtea-web package was installed, the issues exposed via Java applets could have been exploited without user interaction if a user visited a malicious website.

    This erratum also upgrades the OpenJDK package to IcedTea7 2.3.8. Refer to the NEWS file, linked to in the References, for further information.

    All users of java-1.7.0-openjdk are advised to upgrade to these updated packages, which resolve these issues. All running instances of OpenJDK Java must be restarted for the update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2013-0809
    CVE-2013-0809
    CVE-2013-1493
    CVE-2013-1493
    RHSA-2013:0602
    RHSA-2013:0602-01
    RHSA-2013:0602-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.8.0.el6_4
  • AND java-1.7.0-openjdk is signed with Red Hat redhatrelease2 key
  • java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.8.0.el6_4
  • AND java-1.7.0-openjdk-demo is signed with Red Hat redhatrelease2 key
  • java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.8.0.el6_4
  • AND java-1.7.0-openjdk-devel is signed with Red Hat redhatrelease2 key
  • java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.8.0.el6_4
  • AND java-1.7.0-openjdk-javadoc is signed with Red Hat redhatrelease2 key
  • java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.8.0.el6_4
  • AND java-1.7.0-openjdk-src is signed with Red Hat redhatrelease2 key
  • BACK