First published: Wed Apr 27 2016(Updated: )
Adam Gowdiak (Security Explorations) reported that the fix for IBM JDK issue <a href="https://access.redhat.com/security/cve/CVE-2013-5456">CVE-2013-5456</a> (<a class="bz_bug_link bz_status_CLOSED bz_closed bz_public " title="CLOSED ERRATA - CVE-2013-5456 IBM JDK: unspecified sandbox bypass (ORB)" href="show_bug.cgi?id=1027748">bug 1027748</a>), also known as "Issue 70", did not correctly address the problem. Applied fix only restricted access to the vulnerable package, rather then addressing the underlying problem of running untrusted code inside doPrivileged block. Report: <a href="http://seclists.org/fulldisclosure/2016/Apr/43">http://seclists.org/fulldisclosure/2016/Apr/43</a> Write-up of the issue: <a href="http://www.security-explorations.com/materials/SE-2012-01-IBM-5.pdf">http://www.security-explorations.com/materials/SE-2012-01-IBM-5.pdf</a> Proof-of-concept code: <a href="http://www.security-explorations.com/materials/se-2012-01-70.2.zip">http://www.security-explorations.com/materials/se-2012-01-70.2.zip</a>
Affected Software | Affected Version | How to fix |
---|---|---|
IBM JDK 8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1330986 is considered critical due to its potential impact on system integrity.
To fix REDHAT-BUG-1330986, users should update their IBM JDK to the latest version available.
REDHAT-BUG-1330986 specifically affects IBM JDK 8.
The vulnerability REDHAT-BUG-1330986 was reported by Adam Gowdiak from Security Explorations.
REDHAT-BUG-1330986 relates to a previously addressed issue regarding CVE-2013-5456.