CVE-2013-0443: Medium severity oracle jre vulnerability
It was discovered that JSSE component in OpenJDK did not properly validate Diffie-Hellman public keys. A malicious SSL/TLS client could use this flaw to perform a small subgroup attack on the Diffie-Hellman protocol, resulting in weak session key to be negotiated for the connection, or possibly disclose portions of the server's Diffie-Hellman private key.
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.240 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect validation of Diffie-Hellman keys, which allows remote attackers to conduct a "small subgroup attack" to force the use of weak session keys or obtain sensitive information about the private key.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0443?
CVE-2013-0443 is classified as a moderate-severity vulnerability.
How do I fix CVE-2013-0443?
To fix CVE-2013-0443, update to the fixed versions of the affected packages as specified in the remediation list.
Which versions are affected by CVE-2013-0443?
CVE-2013-0443 affects multiple versions of Oracle JDK, Oracle JRE, and IcedTea packages prior to the specified remedial versions.
What types of attacks can exploit CVE-2013-0443?
CVE-2013-0443 can be exploited through a small subgroup attack on the Diffie-Hellman protocol.
What is the impact of exploiting CVE-2013-0443?
Exploiting CVE-2013-0443 may lead to weak session keys being negotiated, compromising the security of SSL/TLS connections.