First published: Mon Oct 14 2013(Updated: )
It was discovered that various OpenJDK classes that represent cryptographic keys could leak private key information by including sensitive data in strings returned by toString() methods. If a Java application called the toString() method on any of the affected classes, it could possibly lead to an unexpected exposure of sensitive key data.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/icedtea | <2.4.3 | 2.4.3 |
redhat/icedtea | <1.11.14 | 1.11.14 |
redhat/icedtea | <1.12.7 | 1.12.7 |
Oracle Java SE 7 | <=1.5.0 | |
Oracle Java SE 7 | =1.5.0-update36 | |
Oracle Java SE 7 | =1.5.0-update38 | |
Oracle Java SE 7 | =1.5.0-update40 | |
Oracle Java SE 7 | =1.5.0-update41 | |
Oracle Java SE 7 | =1.5.0-update45 | |
Java Development Kit (JDK) | =1.5.0 | |
Java Development Kit (JDK) | =1.5.0-update1 | |
Java Development Kit (JDK) | =1.5.0-update10 | |
Java Development Kit (JDK) | =1.5.0-update11 | |
Java Development Kit (JDK) | =1.5.0-update11_b03 | |
Java Development Kit (JDK) | =1.5.0-update12 | |
Java Development Kit (JDK) | =1.5.0-update13 | |
Java Development Kit (JDK) | =1.5.0-update14 | |
Java Development Kit (JDK) | =1.5.0-update15 | |
Java Development Kit (JDK) | =1.5.0-update16 | |
Java Development Kit (JDK) | =1.5.0-update17 | |
Java Development Kit (JDK) | =1.5.0-update18 | |
Java Development Kit (JDK) | =1.5.0-update19 | |
Java Development Kit (JDK) | =1.5.0-update2 | |
Java Development Kit (JDK) | =1.5.0-update20 | |
Java Development Kit (JDK) | =1.5.0-update21 | |
Java Development Kit (JDK) | =1.5.0-update22 | |
Java Development Kit (JDK) | =1.5.0-update23 | |
Java Development Kit (JDK) | =1.5.0-update24 | |
Java Development Kit (JDK) | =1.5.0-update25 | |
Java Development Kit (JDK) | =1.5.0-update26 | |
Java Development Kit (JDK) | =1.5.0-update27 | |
Java Development Kit (JDK) | =1.5.0-update28 | |
Java Development Kit (JDK) | =1.5.0-update29 | |
Java Development Kit (JDK) | =1.5.0-update3 | |
Java Development Kit (JDK) | =1.5.0-update31 | |
Java Development Kit (JDK) | =1.5.0-update33 | |
Java Development Kit (JDK) | =1.5.0-update4 | |
Java Development Kit (JDK) | =1.5.0-update5 | |
Java Development Kit (JDK) | =1.5.0-update6 | |
Java Development Kit (JDK) | =1.5.0-update7 | |
Java Development Kit (JDK) | =1.5.0-update7_b03 | |
Java Development Kit (JDK) | =1.5.0-update8 | |
Java Development Kit (JDK) | =1.5.0-update9 | |
Oracle JRE | <=1.5.0 | |
Oracle JRE | =1.5.0-update36 | |
Oracle JRE | =1.5.0-update38 | |
Oracle JRE | =1.5.0-update40 | |
Oracle JRE | =1.5.0-update41 | |
Oracle JRE | =1.5.0-update45 | |
Sun Java Runtime Environment (JRE) | =1.5.0 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update1 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update10 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update11 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update12 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update13 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update14 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update15 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update16 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update17 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update18 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update19 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update2 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update20 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update21 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update22 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update23 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update24 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update25 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update26 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update27 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update28 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update29 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update3 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update31 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update33 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update4 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update5 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update6 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update7 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update8 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update9 | |
Oracle JRE | <=1.6.0 | |
Oracle JRE | =1.6.0-update22 | |
Oracle JRE | =1.6.0-update23 | |
Oracle JRE | =1.6.0-update24 | |
Oracle JRE | =1.6.0-update25 | |
Oracle JRE | =1.6.0-update26 | |
Oracle JRE | =1.6.0-update27 | |
Oracle JRE | =1.6.0-update29 | |
Oracle JRE | =1.6.0-update30 | |
Oracle JRE | =1.6.0-update31 | |
Oracle JRE | =1.6.0-update32 | |
Oracle JRE | =1.6.0-update33 | |
Oracle JRE | =1.6.0-update34 | |
Oracle JRE | =1.6.0-update35 | |
Oracle JRE | =1.6.0-update37 | |
Oracle JRE | =1.6.0-update38 | |
Oracle JRE | =1.6.0-update39 | |
Oracle JRE | =1.6.0-update41 | |
Oracle JRE | =1.6.0-update43 | |
Oracle JRE | =1.6.0-update45 | |
Oracle JRE | =1.6.0-update51 | |
Sun Java Runtime Environment (JRE) | =1.6.0 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_1 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_10 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_11 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_12 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_13 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_14 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_15 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_16 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_17 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_18 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_19 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_2 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_20 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_21 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_3 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_4 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_5 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_6 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_7 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_9 | |
Oracle Java SE 7 | <=1.7.0 | |
Oracle Java SE 7 | =1.7.0 | |
Oracle Java SE 7 | =1.7.0-update1 | |
Oracle Java SE 7 | =1.7.0-update10 | |
Oracle Java SE 7 | =1.7.0-update11 | |
Oracle Java SE 7 | =1.7.0-update13 | |
Oracle Java SE 7 | =1.7.0-update15 | |
Oracle Java SE 7 | =1.7.0-update17 | |
Oracle Java SE 7 | =1.7.0-update2 | |
Oracle Java SE 7 | =1.7.0-update21 | |
Oracle Java SE 7 | =1.7.0-update25 | |
Oracle Java SE 7 | =1.7.0-update3 | |
Oracle Java SE 7 | =1.7.0-update4 | |
Oracle Java SE 7 | =1.7.0-update5 | |
Oracle Java SE 7 | =1.7.0-update6 | |
Oracle Java SE 7 | =1.7.0-update7 | |
Oracle Java SE 7 | =1.7.0-update9 | |
Oracle Java SE | <=r27.7.6 | |
Oracle Java SE | =r27.7.1 | |
Oracle Java SE | =r27.7.2 | |
Oracle Java SE | =r27.7.3 | |
Oracle Java SE | =r27.7.4 | |
Oracle Java SE | =r27.7.5 | |
Oracle JRE | <=1.7.0 | |
Oracle JRE | =1.7.0 | |
Oracle JRE | =1.7.0-update1 | |
Oracle JRE | =1.7.0-update10 | |
Oracle JRE | =1.7.0-update11 | |
Oracle JRE | =1.7.0-update13 | |
Oracle JRE | =1.7.0-update15 | |
Oracle JRE | =1.7.0-update17 | |
Oracle JRE | =1.7.0-update2 | |
Oracle JRE | =1.7.0-update21 | |
Oracle JRE | =1.7.0-update25 | |
Oracle JRE | =1.7.0-update3 | |
Oracle JRE | =1.7.0-update4 | |
Oracle JRE | =1.7.0-update5 | |
Oracle JRE | =1.7.0-update6 | |
Oracle JRE | =1.7.0-update7 | |
Oracle JRE | =1.7.0-update9 | |
Oracle Java SE 7 | <=1.6.0 | |
Oracle Java SE 7 | =1.6.0-update22 | |
Oracle Java SE 7 | =1.6.0-update23 | |
Oracle Java SE 7 | =1.6.0-update24 | |
Oracle Java SE 7 | =1.6.0-update25 | |
Oracle Java SE 7 | =1.6.0-update26 | |
Oracle Java SE 7 | =1.6.0-update27 | |
Oracle Java SE 7 | =1.6.0-update29 | |
Oracle Java SE 7 | =1.6.0-update30 | |
Oracle Java SE 7 | =1.6.0-update31 | |
Oracle Java SE 7 | =1.6.0-update32 | |
Oracle Java SE 7 | =1.6.0-update33 | |
Oracle Java SE 7 | =1.6.0-update34 | |
Oracle Java SE 7 | =1.6.0-update35 | |
Oracle Java SE 7 | =1.6.0-update37 | |
Oracle Java SE 7 | =1.6.0-update38 | |
Oracle Java SE 7 | =1.6.0-update39 | |
Oracle Java SE 7 | =1.6.0-update41 | |
Oracle Java SE 7 | =1.6.0-update43 | |
Oracle Java SE 7 | =1.6.0-update45 | |
Oracle Java SE 7 | =1.6.0-update51 | |
Java Development Kit (JDK) | =1.6.0 | |
Java Development Kit (JDK) | =1.6.0-update_10 | |
Java Development Kit (JDK) | =1.6.0-update_11 | |
Java Development Kit (JDK) | =1.6.0-update_12 | |
Java Development Kit (JDK) | =1.6.0-update_13 | |
Java Development Kit (JDK) | =1.6.0-update_14 | |
Java Development Kit (JDK) | =1.6.0-update_15 | |
Java Development Kit (JDK) | =1.6.0-update_16 | |
Java Development Kit (JDK) | =1.6.0-update_17 | |
Java Development Kit (JDK) | =1.6.0-update_18 | |
Java Development Kit (JDK) | =1.6.0-update_19 | |
Java Development Kit (JDK) | =1.6.0-update_20 | |
Java Development Kit (JDK) | =1.6.0-update_21 | |
Java Development Kit (JDK) | =1.6.0-update_3 | |
Java Development Kit (JDK) | =1.6.0-update_4 | |
Java Development Kit (JDK) | =1.6.0-update_5 | |
Java Development Kit (JDK) | =1.6.0-update_6 | |
Java Development Kit (JDK) | =1.6.0-update_7 | |
Java Development Kit (JDK) | =1.6.0-update1 | |
Java Development Kit (JDK) | =1.6.0-update1_b06 | |
Java Development Kit (JDK) | =1.6.0-update2 | |
Oracle Java SE | <=r28.2.8 | |
Oracle Java SE | =r28.0.0 | |
Oracle Java SE | =r28.0.1 | |
Oracle Java SE | =r28.0.2 | |
Oracle Java SE | =r28.1.0 | |
Oracle Java SE | =r28.1.1 | |
Oracle Java SE | =r28.1.3 | |
Oracle Java SE | =r28.1.4 | |
Oracle Java SE | =r28.1.5 | |
Oracle Java SE | =r28.2.2 | |
Oracle Java SE | =r28.2.3 | |
Oracle Java SE | =r28.2.4 | |
Oracle Java SE | =r28.2.5 | |
Oracle Java SE | =r28.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5780 has a severity rating of high due to the potential for sensitive data leakage.
To mitigate CVE-2013-5780, upgrade to a fixed version of OpenJDK or IcedTea that addresses the vulnerability.
CVE-2013-5780 affects various versions of OpenJDK and IcedTea, specifically versions up to 2.4.3 and certain 1.5.0 updates.
Java applications utilizing affected OpenJDK classes that call the toString() method may expose sensitive key information.
The implications of CVE-2013-5780 include the risk of private key information being revealed through logging or output methods.