First published: Fri Jul 12 2013(Updated: )
The July 2013 updates for the IBM JDK (5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5) contain patches for unspecified security flaws. For the majority of the flaws, upstream has provided a CVSSv2 base score of 9.3, which suggests a CVSSv2 vector of AV:N/AC:M/Au:N/C:P/I:P/A:P. The exception is <a href="https://access.redhat.com/security/cve/CVE-2013-4002">CVE-2013-4002</a> with a CVSSv2 base score of 7.1. CVE CVSSv2 Score Fixed in <a href="https://access.redhat.com/security/cve/CVE-2013-3006">CVE-2013-3006</a> 9.3 7 SR5 <a href="https://access.redhat.com/security/cve/CVE-2013-3007">CVE-2013-3007</a> 9.3 6.0.1 SR6, 7 SR5 <a href="https://access.redhat.com/security/cve/CVE-2013-3008">CVE-2013-3008</a> 9.3 7 SR5 <a href="https://access.redhat.com/security/cve/CVE-2013-3009">CVE-2013-3009</a> 9.3 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5 <a href="https://access.redhat.com/security/cve/CVE-2013-3010">CVE-2013-3010</a> 9.3 6.0.1 SR6, 7 SR5 <a href="https://access.redhat.com/security/cve/CVE-2013-3011">CVE-2013-3011</a> 9.3 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5 <a href="https://access.redhat.com/security/cve/CVE-2013-3012">CVE-2013-3012</a> 9.3 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5 <a href="https://access.redhat.com/security/cve/CVE-2013-4002">CVE-2013-4002</a> 7.1 5.0 SR16-FP3, 6 SR14, 6.0.1 SR6, 7 SR5 References: <a href="https://www.ibm.com/developerworks/java/jdk/alerts/">https://www.ibm.com/developerworks/java/jdk/alerts/</a> <a href="http://www.ibm.com/developerworks/java/jdk/aix/j764/Java7_64.fixes.html#SR5">http://www.ibm.com/developerworks/java/jdk/aix/j764/Java7_64.fixes.html#SR5</a> <a href="http://www.ibm.com/developerworks/java/jdk/aix/j664/Java6_64.fixes.html#SR14">http://www.ibm.com/developerworks/java/jdk/aix/j664/Java6_64.fixes.html#SR14</a> <a href="http://www.ibm.com/developerworks/java/jdk/aix/j564/fixes.html#SR16FP3">http://www.ibm.com/developerworks/java/jdk/aix/j564/fixes.html#SR16FP3</a>
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.7.0-ibm-1:1.7.0.5.0-1jpp.2.el5_9 | 1.7.0-ibm-1:1.7.0.5.0-1jpp.2.el5_9 |
redhat/java | <1.7.0-ibm-1:1.7.0.5.0-1jpp.2.el6_4 | 1.7.0-ibm-1:1.7.0.5.0-1jpp.2.el6_4 |
IBM JDK | =7.0.0.0 | |
IBM JDK | =7.0.1.0 | |
IBM JDK | =7.0.2.0 | |
IBM JDK | =7.0.3.0 | |
IBM JDK | =7.0.4.0 | |
IBM JDK | =7.0.4.1 | |
IBM JDK | =7.0.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3006 has a CVSSv2 base score of 9.3, indicating high severity.
To fix CVE-2013-3006, update to the latest version of the IBM JDK as specified by your distribution.
CVE-2013-3006 affects multiple versions of IBM JDK, including 5.0 SR16-FP3, 6 SR14, and several 7.x versions.
CVE-2013-3006 includes unspecified security flaws that could potentially compromise confidentiality, integrity, and availability.
Yes, CVE-2013-3006 remains a risk if affected versions of the IBM JDK are in use without updates.