RHSA-2013:1014: Important: java-1.6.0-openjdk security update

Published Jul 3, 2013
·
Updated

These packages provide the OpenJDK 6 Java Runtime Environment and theOpenJDK 6 Software Development Kit.Multiple flaws were discovered in the ImagingLib and the image attribute,channel, layout and raster processing in the 2D component. An untrustedJava application or applet could possibly use these flaws to trigger JavaVirtual Machine memory corruption. (CVE-2013-2470, CVE-2013-2471,CVE-2013-2472, CVE-2013-2473, CVE-2013-2463, CVE-2013-2465, CVE-2013-2469)Integer overflow flaws were found in the way AWT processed certain input.An attacker could use these flaws to execute arbitrary code with theprivileges of the user running an untrusted Java applet or application.(CVE-2013-2459)Multiple improper permission check issues were discovered in the Sound andJMX components in OpenJDK. An untrusted Java application or applet coulduse these flaws to bypass Java sandbox restrictions. (CVE-2013-2448,CVE-2013-2457, CVE-2013-2453)Multiple flaws in the Serialization, Networking, Libraries and CORBAcomponents can be exploited by an untrusted Java application or applet togain access to potentially sensitive information. (CVE-2013-2456,CVE-2013-2447, CVE-2013-2455, CVE-2013-2452, CVE-2013-2443, CVE-2013-2446)It was discovered that the Hotspot component did not properly handleout-of-memory errors. An untrusted Java application or applet couldpossibly use these flaws to terminate the Java Virtual Machine.(CVE-2013-2445)It was discovered that the AWT component did not properly manage certainresources and that the ObjectStreamClass of the Serialization componentdid not properly handle circular references. An untrusted Java applicationor applet could possibly use these flaws to cause a denial of service.(CVE-2013-2444, CVE-2013-2450)It was discovered that the Libraries component contained certain errorsrelated to XML security and the class loader. A remote attacker couldpossibly exploit these flaws to bypass intended security mechanisms ordisclose potentially sensitive information and cause a denial of service.(CVE-2013-2407, CVE-2013-2461)It was discovered that JConsole did not properly inform the user whenestablishing an SSL connection failed. An attacker could exploit this flawto gain access to potentially sensitive information. (CVE-2013-2412)It was found that documentation generated by Javadoc was vulnerable to aframe injection attack. If such documentation was accessible over anetwork, and a remote attacker could trick a user into visiting aspecially-crafted URL, it would lead to arbitrary web content beingdisplayed next to the documentation. This could be used to perform aphishing attack by providing frame content that spoofed a login form onthe site hosting the vulnerable documentation. (CVE-2013-1571)It was discovered that the 2D component created shared memory segments withinsecure permissions. A local attacker could use this flaw to read or writeto the shared memory segment. (CVE-2013-1500)Red Hat would like to thank US-CERT for reporting CVE-2013-1571, and TimBrown for reporting CVE-2013-1500. US-CERT acknowledges Oracle as theoriginal reporter of CVE-2013-1571.All users of java-1.6.0-openjdk are advised to upgrade to these updatedpackages, which resolve these issues. All running instances of OpenJDK Javamust be restarted for the update to take effect.

Affected Software

24 affected componentsFixes available
redhat/java<1.6.0-openjdk-1.6.0.0-1.62.1.11.11.90.el6_4
1.6.0-openjdk-1.6.0.0-1.62.1.11.11.90.el6_4
redhat/java<1.6.0-openjdk-1.6.0.0-1.62.1.11.11.90.el6_4
1.6.0-openjdk-1.6.0.0-1.62.1.11.11.90.el6_4
redhat/java<1.6.0-openjdk-debuginfo-1.6.0.0-1.62.1.11.11.90.el6_4
1.6.0-openjdk-debuginfo-1.6.0.0-1.62.1.11.11.90.el6_4
redhat/java<1.6.0-openjdk-demo-1.6.0.0-1.62.1.11.11.90.el6_4
1.6.0-openjdk-demo-1.6.0.0-1.62.1.11.11.90.el6_4
redhat/java<1.6.0-openjdk-devel-1.6.0.0-1.62.1.11.11.90.el6_4
1.6.0-openjdk-devel-1.6.0.0-1.62.1.11.11.90.el6_4
redhat/java<1.6.0-openjdk-javadoc-1.6.0.0-1.62.1.11.11.90.el6_4
1.6.0-openjdk-javadoc-1.6.0.0-1.62.1.11.11.90.el6_4
redhat/java<1.6.0-openjdk-src-1.6.0.0-1.62.1.11.11.90.el6_4
1.6.0-openjdk-src-1.6.0.0-1.62.1.11.11.90.el6_4
redhat/java<1.6.0-openjdk-debuginfo-1.6.0.0-1.62.1.11.11.90.el6_4
1.6.0-openjdk-debuginfo-1.6.0.0-1.62.1.11.11.90.el6_4
redhat/java<1.6.0-openjdk-demo-1.6.0.0-1.62.1.11.11.90.el6_4
1.6.0-openjdk-demo-1.6.0.0-1.62.1.11.11.90.el6_4
redhat/java<1.6.0-openjdk-devel-1.6.0.0-1.62.1.11.11.90.el6_4
1.6.0-openjdk-devel-1.6.0.0-1.62.1.11.11.90.el6_4
redhat/java<1.6.0-openjdk-javadoc-1.6.0.0-1.62.1.11.11.90.el6_4
1.6.0-openjdk-javadoc-1.6.0.0-1.62.1.11.11.90.el6_4
redhat/java<1.6.0-openjdk-src-1.6.0.0-1.62.1.11.11.90.el6_4
1.6.0-openjdk-src-1.6.0.0-1.62.1.11.11.90.el6_4
redhat/java<1.6.0-openjdk-1.6.0.0-1.41.1.11.11.90.el5_9
1.6.0-openjdk-1.6.0.0-1.41.1.11.11.90.el5_9
redhat/java<1.6.0-openjdk-1.6.0.0-1.41.1.11.11.90.el5_9
1.6.0-openjdk-1.6.0.0-1.41.1.11.11.90.el5_9
redhat/java<1.6.0-openjdk-debuginfo-1.6.0.0-1.41.1.11.11.90.el5_9
1.6.0-openjdk-debuginfo-1.6.0.0-1.41.1.11.11.90.el5_9
redhat/java<1.6.0-openjdk-demo-1.6.0.0-1.41.1.11.11.90.el5_9
1.6.0-openjdk-demo-1.6.0.0-1.41.1.11.11.90.el5_9
redhat/java<1.6.0-openjdk-devel-1.6.0.0-1.41.1.11.11.90.el5_9
1.6.0-openjdk-devel-1.6.0.0-1.41.1.11.11.90.el5_9
redhat/java<1.6.0-openjdk-javadoc-1.6.0.0-1.41.1.11.11.90.el5_9
1.6.0-openjdk-javadoc-1.6.0.0-1.41.1.11.11.90.el5_9
redhat/java<1.6.0-openjdk-src-1.6.0.0-1.41.1.11.11.90.el5_9
1.6.0-openjdk-src-1.6.0.0-1.41.1.11.11.90.el5_9
redhat/java<1.6.0-openjdk-debuginfo-1.6.0.0-1.41.1.11.11.90.el5_9
1.6.0-openjdk-debuginfo-1.6.0.0-1.41.1.11.11.90.el5_9
redhat/java<1.6.0-openjdk-demo-1.6.0.0-1.41.1.11.11.90.el5_9
1.6.0-openjdk-demo-1.6.0.0-1.41.1.11.11.90.el5_9
redhat/java<1.6.0-openjdk-devel-1.6.0.0-1.41.1.11.11.90.el5_9
1.6.0-openjdk-devel-1.6.0.0-1.41.1.11.11.90.el5_9
redhat/java<1.6.0-openjdk-javadoc-1.6.0.0-1.41.1.11.11.90.el5_9
1.6.0-openjdk-javadoc-1.6.0.0-1.41.1.11.11.90.el5_9
redhat/java<1.6.0-openjdk-src-1.6.0.0-1.41.1.11.11.90.el5_9
1.6.0-openjdk-src-1.6.0.0-1.41.1.11.11.90.el5_9

Remediation

Event History

Jul 3, 2013
Advisory Published
12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of RHSA-2013:1014?

The severity of RHSA-2013:1014 is rated as important due to multiple flaws identified in OpenJDK 6 that could lead to potential exploitation.

2

How do I fix RHSA-2013:1014?

To fix RHSA-2013:1014, you should update to the patched version of OpenJDK 6, which is 1.6.0-openjdk-1.6.0.0-1.62.1.11.11.90.el6_4.

3

What software is affected by RHSA-2013:1014?

RHSA-2013:1014 affects multiple packages of OpenJDK 6, including the Java Runtime Environment and the Software Development Kit.

4

Is RHSA-2013:1014 applicable to all systems?

RHSA-2013:1014 is specifically applicable to systems using Red Hat's OpenJDK 6 packages on Enterprise Linux versions el5_9 and el6_4.

5

Are there any known exploits for RHSA-2013:1014?

Yes, there have been reports of potential exploitation through untrusted Java applications due to the vulnerabilities described in RHSA-2013:1014.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203