int(6701)

Vulnerability Bulletins


Actualización de seguridad java-1.7.0-ibm

Vulnerability classification

Property Value
Confidence level official+tested
Impact Obtener acceso
Dificulty Avanzado
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer Comercial Software
Affected software RHEL Desktop Supplementary (v. 5 client)
RHEL Supplementary (v. 5 server)
Red Hat Enterprise Linux Desktop Supplementary (v. 6)
Red Hat Enterprise Linux HPC Node Supplementary (v. 6)
Red Hat Enterprise Linux Server Supplementary (v. 6)
Red Hat Enterprise Linux Server Supplementary EUS (v. 6.4.z)
Red Hat Enterprise Linux Workstation Supplementary (v. 6)

Description

IBM Java SE versión 7 incluye IBM Java Runtime Environment y el IBM
Java Software Development Kit.
Esta actualización resuelve varias vulnerabilidades en IBM Java Runtime Environment y el IBM Java Software Development Kit.

Se han encontrado varias vulnerabilidades mediante las cuales un atacante remoto puede afectar a la confidencialidad, integridad y disponibilidad de datos, mediante vectores manipulados.
Otro tipo de vulnerabilidades encontradas, permiten la ejecución arbitraria de código mediante la manipulación de vectores.

También se ha encontrado vulnerabilidades que permitían saltarse medidas de seguridad de Java.

Se ha corroborado la existencia de una vulnerabilidad que permitía la execución remota de código o la causa de una denegación de servicio mediante una imagen con parámetros manipulados.

Solution

Aplicar la última actualización disponible.

Standar resources

Property Value
CVE CVE-2012-1541
CVE-2012-3174
CVE-2012-3213
CVE-2012-3342
CVE-2013-0351
CVE-2013-0409
CVE-2013-0419
CVE-2013-0422
CVE-2013-0423
CVE-2013-0424
CVE-2013-0425
CVE-2013-0426
CVE-2013-0427
CVE-2013-0428
CVE-2013-0431
CVE-2013-0432
CVE-2013-0433
CVE-2013-0434
CVE-2013-0435
CVE-2013-0437
CVE-2013-0438
CVE-2013-0440
CVE-2013-0441
CVE-2013-0442
CVE-2013-0443
CVE-2013-0444
CVE-2013-0445
CVE-2013-0446
CVE-2013-0449
CVE-2013-0450
CVE-2013-0809
CVE-2013-1473
CVE-2013-1476
CVE-2013-1478
CVE-2013-1480
CVE-2013-1484
CVE-2013-1485
CVE-2013-1486
CVE-2013-1487
CVE-2013-1493
BID

Other resources

Boletín de seguridad de RedHat
http://rhn.redhat.com/errata/RHSA-2013-0626.html

Version history

Version Comments Date
1.0 Aviso emitido 2013-03-12