IBM Java SDK updates 7 SR4-FP1, 6 SR13-FP1, 5.0 SR16-FP1 and 1.4.2 SR13-FP16 fix an unspecified security issue listed in release notes as:
IV38147 196141 Class Libraries FIX SECURITY VULNERABILITY CVE-2013-0485
http://www.ibm.com/developerworks/java/jdk/aix/j732/Java7.fixes.html#SR4FP1 http://www.ibm.com/developerworks/java/jdk/aix/j664/Java664.fixes.html#SR13FP1 http://www.ibm.com/developerworks/java/jdk/aix/j532/fixes.html#SR16FP1 http://www.ibm.com/developerworks/java/jdk/aix/14264/fixes.html#SR13FP16
No further details are currently available for this issue.
The class file parser in IBM Java before 1.4.2 SR13 FP9, as used in IBM Runtimes for Java Technology 5.0.0 before SR13 and 6.0.0 before SR10, allows remote authenticated users to cause a denial of service (JVM segmentation fault, and possibly memory consumption or an infinite loop) via a crafted attribute length field in a class file, which triggers a buffer over-read.