First published: Mon Oct 14 2013(Updated: )
It was discovered that getDeclaringClass() method implementation did not perform class loader package access checks. In certain configurations, an untrusted Java application or applet could possibly use this flaw to bypass certain Java sandbox restrictions.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/icedtea | <2.4.3 | 2.4.3 |
redhat/icedtea | <1.11.14 | 1.11.14 |
redhat/icedtea | <1.12.7 | 1.12.7 |
Oracle JDK | <=1.5.0 | |
Oracle JDK | =1.5.0-update36 | |
Oracle JDK | =1.5.0-update38 | |
Oracle JDK | =1.5.0-update40 | |
Oracle JDK | =1.5.0-update41 | |
Oracle JDK | =1.5.0-update45 | |
Java Development Kit (JDK) | =1.5.0 | |
Java Development Kit (JDK) | =1.5.0-update1 | |
Java Development Kit (JDK) | =1.5.0-update10 | |
Java Development Kit (JDK) | =1.5.0-update11 | |
Java Development Kit (JDK) | =1.5.0-update11_b03 | |
Java Development Kit (JDK) | =1.5.0-update12 | |
Java Development Kit (JDK) | =1.5.0-update13 | |
Java Development Kit (JDK) | =1.5.0-update14 | |
Java Development Kit (JDK) | =1.5.0-update15 | |
Java Development Kit (JDK) | =1.5.0-update16 | |
Java Development Kit (JDK) | =1.5.0-update17 | |
Java Development Kit (JDK) | =1.5.0-update18 | |
Java Development Kit (JDK) | =1.5.0-update19 | |
Java Development Kit (JDK) | =1.5.0-update2 | |
Java Development Kit (JDK) | =1.5.0-update20 | |
Java Development Kit (JDK) | =1.5.0-update21 | |
Java Development Kit (JDK) | =1.5.0-update22 | |
Java Development Kit (JDK) | =1.5.0-update23 | |
Java Development Kit (JDK) | =1.5.0-update24 | |
Java Development Kit (JDK) | =1.5.0-update25 | |
Java Development Kit (JDK) | =1.5.0-update26 | |
Java Development Kit (JDK) | =1.5.0-update27 | |
Java Development Kit (JDK) | =1.5.0-update28 | |
Java Development Kit (JDK) | =1.5.0-update29 | |
Java Development Kit (JDK) | =1.5.0-update3 | |
Java Development Kit (JDK) | =1.5.0-update31 | |
Java Development Kit (JDK) | =1.5.0-update33 | |
Java Development Kit (JDK) | =1.5.0-update4 | |
Java Development Kit (JDK) | =1.5.0-update5 | |
Java Development Kit (JDK) | =1.5.0-update6 | |
Java Development Kit (JDK) | =1.5.0-update7 | |
Java Development Kit (JDK) | =1.5.0-update7_b03 | |
Java Development Kit (JDK) | =1.5.0-update8 | |
Java Development Kit (JDK) | =1.5.0-update9 | |
Oracle Java SE JDK and JRE | <=1.7.0 | |
Oracle Java SE JDK and JRE | =1.7.0 | |
Oracle Java SE JDK and JRE | =1.7.0-update1 | |
Oracle Java SE JDK and JRE | =1.7.0-update10 | |
Oracle Java SE JDK and JRE | =1.7.0-update11 | |
Oracle Java SE JDK and JRE | =1.7.0-update13 | |
Oracle Java SE JDK and JRE | =1.7.0-update15 | |
Oracle Java SE JDK and JRE | =1.7.0-update17 | |
Oracle Java SE JDK and JRE | =1.7.0-update2 | |
Oracle Java SE JDK and JRE | =1.7.0-update21 | |
Oracle Java SE JDK and JRE | =1.7.0-update25 | |
Oracle Java SE JDK and JRE | =1.7.0-update3 | |
Oracle Java SE JDK and JRE | =1.7.0-update4 | |
Oracle Java SE JDK and JRE | =1.7.0-update5 | |
Oracle Java SE JDK and JRE | =1.7.0-update6 | |
Oracle Java SE JDK and JRE | =1.7.0-update7 | |
Oracle Java SE JDK and JRE | =1.7.0-update9 | |
Oracle JDK | <=1.7.0 | |
Oracle JDK | =1.7.0 | |
Oracle JDK | =1.7.0-update1 | |
Oracle JDK | =1.7.0-update10 | |
Oracle JDK | =1.7.0-update11 | |
Oracle JDK | =1.7.0-update13 | |
Oracle JDK | =1.7.0-update15 | |
Oracle JDK | =1.7.0-update17 | |
Oracle JDK | =1.7.0-update2 | |
Oracle JDK | =1.7.0-update21 | |
Oracle JDK | =1.7.0-update25 | |
Oracle JDK | =1.7.0-update3 | |
Oracle JDK | =1.7.0-update4 | |
Oracle JDK | =1.7.0-update5 | |
Oracle JDK | =1.7.0-update6 | |
Oracle JDK | =1.7.0-update7 | |
Oracle JDK | =1.7.0-update9 | |
Oracle Java SE JDK and JRE | <=1.5.0 | |
Oracle Java SE JDK and JRE | =1.5.0-update36 | |
Oracle Java SE JDK and JRE | =1.5.0-update38 | |
Oracle Java SE JDK and JRE | =1.5.0-update40 | |
Oracle Java SE JDK and JRE | =1.5.0-update41 | |
Oracle Java SE JDK and JRE | =1.5.0-update45 | |
Sun Java Runtime Environment (JRE) | =1.5.0 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update1 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update10 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update11 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update12 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update13 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update14 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update15 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update16 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update17 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update18 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update19 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update2 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update20 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update21 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update22 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update23 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update24 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update25 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update26 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update27 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update28 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update29 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update3 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update31 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update33 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update4 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update5 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update6 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update7 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update8 | |
Sun Java Runtime Environment (JRE) | =1.5.0-update9 | |
Oracle JDK | <=1.6.0 | |
Oracle JDK | =1.6.0-update22 | |
Oracle JDK | =1.6.0-update23 | |
Oracle JDK | =1.6.0-update24 | |
Oracle JDK | =1.6.0-update25 | |
Oracle JDK | =1.6.0-update26 | |
Oracle JDK | =1.6.0-update27 | |
Oracle JDK | =1.6.0-update29 | |
Oracle JDK | =1.6.0-update30 | |
Oracle JDK | =1.6.0-update31 | |
Oracle JDK | =1.6.0-update32 | |
Oracle JDK | =1.6.0-update33 | |
Oracle JDK | =1.6.0-update34 | |
Oracle JDK | =1.6.0-update35 | |
Oracle JDK | =1.6.0-update37 | |
Oracle JDK | =1.6.0-update38 | |
Oracle JDK | =1.6.0-update39 | |
Oracle JDK | =1.6.0-update41 | |
Oracle JDK | =1.6.0-update43 | |
Oracle JDK | =1.6.0-update45 | |
Oracle JDK | =1.6.0-update51 | |
Java Development Kit (JDK) | =1.6.0 | |
Java Development Kit (JDK) | =1.6.0-update_10 | |
Java Development Kit (JDK) | =1.6.0-update_11 | |
Java Development Kit (JDK) | =1.6.0-update_12 | |
Java Development Kit (JDK) | =1.6.0-update_13 | |
Java Development Kit (JDK) | =1.6.0-update_14 | |
Java Development Kit (JDK) | =1.6.0-update_15 | |
Java Development Kit (JDK) | =1.6.0-update_16 | |
Java Development Kit (JDK) | =1.6.0-update_17 | |
Java Development Kit (JDK) | =1.6.0-update_18 | |
Java Development Kit (JDK) | =1.6.0-update_19 | |
Java Development Kit (JDK) | =1.6.0-update_20 | |
Java Development Kit (JDK) | =1.6.0-update_21 | |
Java Development Kit (JDK) | =1.6.0-update_3 | |
Java Development Kit (JDK) | =1.6.0-update_4 | |
Java Development Kit (JDK) | =1.6.0-update_5 | |
Java Development Kit (JDK) | =1.6.0-update_6 | |
Java Development Kit (JDK) | =1.6.0-update_7 | |
Java Development Kit (JDK) | =1.6.0-update1 | |
Java Development Kit (JDK) | =1.6.0-update1_b06 | |
Java Development Kit (JDK) | =1.6.0-update2 | |
Oracle Java SE JDK and JRE | <=1.6.0 | |
Oracle Java SE JDK and JRE | =1.6.0-update22 | |
Oracle Java SE JDK and JRE | =1.6.0-update23 | |
Oracle Java SE JDK and JRE | =1.6.0-update24 | |
Oracle Java SE JDK and JRE | =1.6.0-update25 | |
Oracle Java SE JDK and JRE | =1.6.0-update26 | |
Oracle Java SE JDK and JRE | =1.6.0-update27 | |
Oracle Java SE JDK and JRE | =1.6.0-update29 | |
Oracle Java SE JDK and JRE | =1.6.0-update30 | |
Oracle Java SE JDK and JRE | =1.6.0-update31 | |
Oracle Java SE JDK and JRE | =1.6.0-update32 | |
Oracle Java SE JDK and JRE | =1.6.0-update33 | |
Oracle Java SE JDK and JRE | =1.6.0-update34 | |
Oracle Java SE JDK and JRE | =1.6.0-update35 | |
Oracle Java SE JDK and JRE | =1.6.0-update37 | |
Oracle Java SE JDK and JRE | =1.6.0-update38 | |
Oracle Java SE JDK and JRE | =1.6.0-update39 | |
Oracle Java SE JDK and JRE | =1.6.0-update41 | |
Oracle Java SE JDK and JRE | =1.6.0-update43 | |
Oracle Java SE JDK and JRE | =1.6.0-update45 | |
Oracle Java SE JDK and JRE | =1.6.0-update51 | |
Sun Java Runtime Environment (JRE) | =1.6.0 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_1 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_10 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_11 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_12 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_13 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_14 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_15 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_16 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_17 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_18 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_19 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_2 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_20 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_21 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_3 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_4 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_5 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_6 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_7 | |
Sun Java Runtime Environment (JRE) | =1.6.0-update_9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-5840 is classified as medium due to its impact on the Java sandbox environment.
To fix CVE-2013-5840, upgrade to a non-vulnerable version of the affected software listed in the advisory.
CVE-2013-5840 affects multiple versions of Oracle JDK, Oracle JRE, and IcedTea as specified in the vulnerability description.
CVE-2013-5840 is a class loader package access vulnerability that could lead to bypassing security restrictions.
Exploiting CVE-2013-5840 could potentially allow an untrusted Java application to execute code beyond restricted sandbox boundaries.