First published: Tue Oct 15 2013(Updated: )
It was discovered that java.util.TimeZone does not properly restrict changing the time zone to the default time zone. An untrusted Java application or applet could exploit this to change the default time zone of their application contexts.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/icedtea | <2.4.3 | 2.4.3 |
redhat/icedtea | <1.11.14 | 1.11.14 |
redhat/icedtea | <1.12.7 | 1.12.7 |
Oracle JRE | <=1.7.0 | |
Oracle JRE | =1.7.0 | |
Oracle JRE | =1.7.0-update1 | |
Oracle JRE | =1.7.0-update10 | |
Oracle JRE | =1.7.0-update11 | |
Oracle JRE | =1.7.0-update13 | |
Oracle JRE | =1.7.0-update15 | |
Oracle JRE | =1.7.0-update17 | |
Oracle JRE | =1.7.0-update2 | |
Oracle JRE | =1.7.0-update21 | |
Oracle JRE | =1.7.0-update25 | |
Oracle JRE | =1.7.0-update3 | |
Oracle JRE | =1.7.0-update4 | |
Oracle JRE | =1.7.0-update5 | |
Oracle JRE | =1.7.0-update6 | |
Oracle JRE | =1.7.0-update7 | |
Oracle JRE | =1.7.0-update9 | |
Oracle JRE | <=1.6.0 | |
Oracle JRE | =1.6.0-update22 | |
Oracle JRE | =1.6.0-update23 | |
Oracle JRE | =1.6.0-update24 | |
Oracle JRE | =1.6.0-update25 | |
Oracle JRE | =1.6.0-update26 | |
Oracle JRE | =1.6.0-update27 | |
Oracle JRE | =1.6.0-update29 | |
Oracle JRE | =1.6.0-update30 | |
Oracle JRE | =1.6.0-update31 | |
Oracle JRE | =1.6.0-update32 | |
Oracle JRE | =1.6.0-update33 | |
Oracle JRE | =1.6.0-update34 | |
Oracle JRE | =1.6.0-update35 | |
Oracle JRE | =1.6.0-update37 | |
Oracle JRE | =1.6.0-update38 | |
Oracle JRE | =1.6.0-update39 | |
Oracle JRE | =1.6.0-update41 | |
Oracle JRE | =1.6.0-update43 | |
Oracle JRE | =1.6.0-update45 | |
Oracle JRE | =1.6.0-update51 | |
Sun Java Runtime Environment (JRE) | =1.6.0 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_1 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_10 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_11 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_12 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_13 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_14 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_15 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_16 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_17 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_18 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_19 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_2 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_20 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_21 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_3 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_4 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_5 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_6 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_7 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_9 | |
Oracle JRE | <=1.5.0 | |
Oracle JRE | =1.5.0-update36 | |
Oracle JRE | =1.5.0-update38 | |
Oracle JRE | =1.5.0-update40 | |
Oracle JRE | =1.5.0-update41 | |
Oracle JRE | =1.5.0-update45 | |
Sun Java Runtime Environment (JRE) | =1.5.0 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update1 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update10 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update11 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update12 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update13 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update14 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update15 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update16 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update17 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update18 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update19 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update2 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update20 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update21 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update22 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update23 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update24 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update25 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update26 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update27 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update28 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update29 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update3 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update31 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update33 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update4 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update5 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update6 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update7 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update8 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update9 | |
Oracle OpenJDK 1.8.0 | <=1.7.0 | |
Oracle OpenJDK 1.8.0 | =1.7.0 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update1 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update10 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update11 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update13 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update15 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update17 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update2 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update21 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update25 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update3 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update4 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update5 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update6 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update7 | |
Oracle OpenJDK 1.8.0 | =1.7.0-update9 | |
Oracle OpenJDK 1.8.0 | <=1.6.0 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update22 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update23 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update24 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update25 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update26 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update27 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update29 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update30 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update31 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update32 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update33 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update34 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update35 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update37 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update38 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update39 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update41 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update43 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update45 | |
Oracle OpenJDK 1.8.0 | =1.6.0-update51 | |
Java Development Kit (JDK) | =1.6.0 | |
Java Development Kit (JDK) | =1.6.0-update_10 | |
Java Development Kit (JDK) | =1.6.0-update_11 | |
Java Development Kit (JDK) | =1.6.0-update_12 | |
Java Development Kit (JDK) | =1.6.0-update_13 | |
Java Development Kit (JDK) | =1.6.0-update_14 | |
Java Development Kit (JDK) | =1.6.0-update_15 | |
Java Development Kit (JDK) | =1.6.0-update_16 | |
Java Development Kit (JDK) | =1.6.0-update_17 | |
Java Development Kit (JDK) | =1.6.0-update_18 | |
Java Development Kit (JDK) | =1.6.0-update_19 | |
Java Development Kit (JDK) | =1.6.0-update_20 | |
Java Development Kit (JDK) | =1.6.0-update_21 | |
Java Development Kit (JDK) | =1.6.0-update_3 | |
Java Development Kit (JDK) | =1.6.0-update_4 | |
Java Development Kit (JDK) | =1.6.0-update_5 | |
Java Development Kit (JDK) | =1.6.0-update_6 | |
Java Development Kit (JDK) | =1.6.0-update_7 | |
Java Development Kit (JDK) | =1.6.0-update1 | |
Java Development Kit (JDK) | =1.6.0-update1_b06 | |
Java Development Kit (JDK) | =1.6.0-update2 | |
Oracle OpenJDK 1.8.0 | <=1.5.0 | |
Oracle OpenJDK 1.8.0 | =1.5.0-update36 | |
Oracle OpenJDK 1.8.0 | =1.5.0-update38 | |
Oracle OpenJDK 1.8.0 | =1.5.0-update40 | |
Oracle OpenJDK 1.8.0 | =1.5.0-update41 | |
Oracle OpenJDK 1.8.0 | =1.5.0-update45 | |
Java Development Kit (JDK) | =1.5.0 | |
Java Development Kit (JDK) | =1.5.0-update1 | |
Java Development Kit (JDK) | =1.5.0-update10 | |
Java Development Kit (JDK) | =1.5.0-update11 | |
Java Development Kit (JDK) | =1.5.0-update11_b03 | |
Java Development Kit (JDK) | =1.5.0-update12 | |
Java Development Kit (JDK) | =1.5.0-update13 | |
Java Development Kit (JDK) | =1.5.0-update14 | |
Java Development Kit (JDK) | =1.5.0-update15 | |
Java Development Kit (JDK) | =1.5.0-update16 | |
Java Development Kit (JDK) | =1.5.0-update17 | |
Java Development Kit (JDK) | =1.5.0-update18 | |
Java Development Kit (JDK) | =1.5.0-update19 | |
Java Development Kit (JDK) | =1.5.0-update2 | |
Java Development Kit (JDK) | =1.5.0-update20 | |
Java Development Kit (JDK) | =1.5.0-update21 | |
Java Development Kit (JDK) | =1.5.0-update22 | |
Java Development Kit (JDK) | =1.5.0-update23 | |
Java Development Kit (JDK) | =1.5.0-update24 | |
Java Development Kit (JDK) | =1.5.0-update25 | |
Java Development Kit (JDK) | =1.5.0-update26 | |
Java Development Kit (JDK) | =1.5.0-update27 | |
Java Development Kit (JDK) | =1.5.0-update28 | |
Java Development Kit (JDK) | =1.5.0-update29 | |
Java Development Kit (JDK) | =1.5.0-update3 | |
Java Development Kit (JDK) | =1.5.0-update31 | |
Java Development Kit (JDK) | =1.5.0-update33 | |
Java Development Kit (JDK) | =1.5.0-update4 | |
Java Development Kit (JDK) | =1.5.0-update5 | |
Java Development Kit (JDK) | =1.5.0-update6 | |
Java Development Kit (JDK) | =1.5.0-update7 | |
Java Development Kit (JDK) | =1.5.0-update7_b03 | |
Java Development Kit (JDK) | =1.5.0-update8 | |
Java Development Kit (JDK) | =1.5.0-update9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3829 has been rated as a high severity vulnerability due to its ability to allow untrusted Java applications to alter default time zones.
To fix CVE-2013-3829, users should update affected versions of Java to the latest secure release provided by Oracle or their vendor.
CVE-2013-3829 affects various versions of Oracle JRE and JDK as well as different versions of the IcedTea package.
Yes, CVE-2013-3829 can potentially be exploited remotely by running untrusted Java applications or applets.
Exploitation of CVE-2013-3829 may allow attackers to change application contexts' default time zones, potentially disrupting time-sensitive processes.