First published: Tue Oct 15 2013(Updated: )
It was discovered that ObjectInputStream and ObjectOutputStream serialization handling did not properly perform certain checks. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/icedtea | <2.4.3 | 2.4.3 |
redhat/icedtea | <1.11.14 | 1.11.14 |
redhat/icedtea | <1.12.7 | 1.12.7 |
Oracle JDK 6 | =1.5.0 | |
Oracle JDK 6 | =1.5.0-update1 | |
Oracle JDK 6 | =1.5.0-update10 | |
Oracle JDK 6 | =1.5.0-update11 | |
Oracle JDK 6 | =1.5.0-update12 | |
Oracle JDK 6 | =1.5.0-update13 | |
Oracle JDK 6 | =1.5.0-update14 | |
Oracle JDK 6 | =1.5.0-update15 | |
Oracle JDK 6 | =1.5.0-update16 | |
Oracle JDK 6 | =1.5.0-update17 | |
Oracle JDK 6 | =1.5.0-update18 | |
Oracle JDK 6 | =1.5.0-update19 | |
Oracle JDK 6 | =1.5.0-update2 | |
Oracle JDK 6 | =1.5.0-update20 | |
Oracle JDK 6 | =1.5.0-update21 | |
Oracle JDK 6 | =1.5.0-update22 | |
Oracle JDK 6 | =1.5.0-update23 | |
Oracle JDK 6 | =1.5.0-update24 | |
Oracle JDK 6 | =1.5.0-update25 | |
Oracle JDK 6 | =1.5.0-update26 | |
Oracle JDK 6 | =1.5.0-update27 | |
Oracle JDK 6 | =1.5.0-update28 | |
Oracle JDK 6 | =1.5.0-update29 | |
Oracle JDK 6 | =1.5.0-update3 | |
Oracle JDK 6 | =1.5.0-update30 | |
Oracle JDK 6 | =1.5.0-update31 | |
Oracle JDK 6 | =1.5.0-update32 | |
Oracle JDK 6 | =1.5.0-update33 | |
Oracle JDK 6 | =1.5.0-update34 | |
Oracle JDK 6 | =1.5.0-update35 | |
Oracle JDK 6 | =1.5.0-update36 | |
Oracle JDK 6 | =1.5.0-update38 | |
Oracle JDK 6 | =1.5.0-update39 | |
Oracle JDK 6 | =1.5.0-update4 | |
Oracle JDK 6 | =1.5.0-update40 | |
Oracle JDK 6 | =1.5.0-update41 | |
Oracle JDK 6 | =1.5.0-update45 | |
Oracle JDK 6 | =1.5.0-update5 | |
Oracle JDK 6 | =1.5.0-update51 | |
Oracle JDK 6 | =1.5.0-update6 | |
Oracle JDK 6 | =1.5.0-update7 | |
Oracle JDK 6 | =1.5.0-update8 | |
Oracle JDK 6 | =1.5.0-update9 | |
Oracle JDK 6 | =1.6.0 | |
Oracle JDK 6 | =1.6.0-update1 | |
Oracle JDK 6 | =1.6.0-update10 | |
Oracle JDK 6 | =1.6.0-update11 | |
Oracle JDK 6 | =1.6.0-update12 | |
Oracle JDK 6 | =1.6.0-update13 | |
Oracle JDK 6 | =1.6.0-update14 | |
Oracle JDK 6 | =1.6.0-update15 | |
Oracle JDK 6 | =1.6.0-update16 | |
Oracle JDK 6 | =1.6.0-update17 | |
Oracle JDK 6 | =1.6.0-update18 | |
Oracle JDK 6 | =1.6.0-update19 | |
Oracle JDK 6 | =1.6.0-update2 | |
Oracle JDK 6 | =1.6.0-update20 | |
Oracle JDK 6 | =1.6.0-update21 | |
Oracle JDK 6 | =1.6.0-update22 | |
Oracle JDK 6 | =1.6.0-update23 | |
Oracle JDK 6 | =1.6.0-update24 | |
Oracle JDK 6 | =1.6.0-update25 | |
Oracle JDK 6 | =1.6.0-update26 | |
Oracle JDK 6 | =1.6.0-update27 | |
Oracle JDK 6 | =1.6.0-update29 | |
Oracle JDK 6 | =1.6.0-update3 | |
Oracle JDK 6 | =1.6.0-update30 | |
Oracle JDK 6 | =1.6.0-update31 | |
Oracle JDK 6 | =1.6.0-update32 | |
Oracle JDK 6 | =1.6.0-update32_b31 | |
Oracle JDK 6 | =1.6.0-update32_b32 | |
Oracle JDK 6 | =1.6.0-update33 | |
Oracle JDK 6 | =1.6.0-update33_b31 | |
Oracle JDK 6 | =1.6.0-update33_b32 | |
Oracle JDK 6 | =1.6.0-update33_b33 | |
Oracle JDK 6 | =1.6.0-update34 | |
Oracle JDK 6 | =1.6.0-update34_b31 | |
Oracle JDK 6 | =1.6.0-update34_b32 | |
Oracle JDK 6 | =1.6.0-update35 | |
Oracle JDK 6 | =1.6.0-update35_b31 | |
Oracle JDK 6 | =1.6.0-update35_b32 | |
Oracle JDK 6 | =1.6.0-update37 | |
Oracle JDK 6 | =1.6.0-update37_b31 | |
Oracle JDK 6 | =1.6.0-update37_b32 | |
Oracle JDK 6 | =1.6.0-update38 | |
Oracle JDK 6 | =1.6.0-update38_b31 | |
Oracle JDK 6 | =1.6.0-update39 | |
Oracle JDK 6 | =1.6.0-update4 | |
Oracle JDK 6 | =1.6.0-update41 | |
Oracle JDK 6 | =1.6.0-update43 | |
Oracle JDK 6 | =1.6.0-update43_b31 | |
Oracle JDK 6 | =1.6.0-update45 | |
Oracle JDK 6 | =1.6.0-update5 | |
Oracle JDK 6 | =1.6.0-update51 | |
Oracle JDK 6 | =1.6.0-update51_b31 | |
Oracle JDK 6 | =1.6.0-update51_b32 | |
Oracle JDK 6 | =1.6.0-update6 | |
Oracle JDK 6 | =1.6.0-update60 | |
Oracle JDK 6 | =1.6.0-update7 | |
Oracle JDK 6 | =1.6.0-update8 | |
Oracle JDK 6 | =1.6.0-update9 | |
Oracle JDK 6 | =1.7.0 | |
Oracle JDK 6 | =1.7.0-update1 | |
Oracle JDK 6 | =1.7.0-update10 | |
Oracle JDK 6 | =1.7.0-update10_b31 | |
Oracle JDK 6 | =1.7.0-update11 | |
Oracle JDK 6 | =1.7.0-update11_b32 | |
Oracle JDK 6 | =1.7.0-update13 | |
Oracle JDK 6 | =1.7.0-update15 | |
Oracle JDK 6 | =1.7.0-update17 | |
Oracle JDK 6 | =1.7.0-update17_b31 | |
Oracle JDK 6 | =1.7.0-update17_b32 | |
Oracle JDK 6 | =1.7.0-update2 | |
Oracle JDK 6 | =1.7.0-update21 | |
Oracle JDK 6 | =1.7.0-update21_b31 | |
Oracle JDK 6 | =1.7.0-update25 | |
Oracle JDK 6 | =1.7.0-update25_b33 | |
Oracle JDK 6 | =1.7.0-update25_b34 | |
Oracle JDK 6 | =1.7.0-update25_b35 | |
Oracle JDK 6 | =1.7.0-update3 | |
Oracle JDK 6 | =1.7.0-update4 | |
Oracle JDK 6 | =1.7.0-update40 | |
Oracle JDK 6 | =1.7.0-update5 | |
Oracle JDK 6 | =1.7.0-update6 | |
Oracle JDK 6 | =1.7.0-update7 | |
Oracle JDK 6 | =1.7.0-update9 | |
Oracle Java Runtime Environment (JRE) | =1.5.0 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update1 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update10 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update11 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update12 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update13 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update14 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update15 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update16 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update17 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update18 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update19 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update2 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update20 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update21 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update22 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update23 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update24 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update25 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update26 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update27 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update28 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update29 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update3 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update30 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update31 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update32 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update33 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update34 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update35 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update36 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update38 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update39 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update4 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update40 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update41 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update45 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update5 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update51 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update6 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update7 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update8 | |
Oracle Java Runtime Environment (JRE) | =1.5.0-update9 | |
Oracle Java Runtime Environment (JRE) | =1.6.0 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update1 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update10 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update11 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update12 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update13 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update14 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update15 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update16 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update17 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update18 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update19 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update2 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update20 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update21 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update22 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update23 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update24 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update25 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update26 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update27 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update29 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update3 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update30 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update31 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update32 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update33 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update34 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update35 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update37 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update38 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update39 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update4 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update41 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update43 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update45 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update5 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update51 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update6 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update60 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update7 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update8 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update9 | |
Oracle Java Runtime Environment (JRE) | =1.7.0 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update1 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update10 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update10_b31 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update11 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update11_b32 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update13 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update15 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update17 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update17_b31 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update17_b32 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update2 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update21 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update21_b31 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update25 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update25_b33 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update25_b34 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update25_b35 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update3 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update4 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update40 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update5 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update6 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update7 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update7_b32 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update9 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update9_b31 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update9_b32 | |
redhat enterprise Linux desktop | =5.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux eus | =6.4 | |
redhat enterprise Linux server | =5.0 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server aus | =6.4 | |
redhat enterprise Linux workstation | =5.0 | |
redhat enterprise Linux workstation | =6.0 | |
Ubuntu Linux | =10.04 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =12.10 | |
Ubuntu Linux | =13.04 | |
Ubuntu Linux | =13.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-5842 is classified as high due to potential bypassing of Java sandbox restrictions.
To fix CVE-2013-5842, update affected versions of Oracle JDK and JRE to the latest release or the provided remedies.
CVE-2013-5842 affects Oracle Java SE 7u40 and earlier versions, as well as several versions of IcedTea.
Systems that run untrusted Java applications or applets, particularly those utilizing affected JDK/JRE versions, are at risk from CVE-2013-5842.
Yes, CVE-2013-5842 has been exploited in the wild, allowing attackers to bypass security mechanisms.