The default Java security properties configuration did not restrict access to sub-packages of the com.sun.corba.se package. An untrusted Java application or applet could use this flaw to trigger denial of service. This update lists whole com.sun.corba.se package as restricted in the java.security file.
It was discovered that the Security component in OpenJDK could pass mutable strings to untrusted code. An untrusted Java application or applet could possibly use this flaw to bypass certain Java sandbox restrictions.
Oracle Java SE 5.0u71, 6u71 and 7u51 fixes an unspecified vulnerability in the Install component (CVE-2013-5905). Upstream has CVSSv2 scored this issue as: 5.1/AV:N/AC:H/Au:N/C:P/I:P/A:P
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html#AppendixJAVA
Oracle Java SE 5.0u71, 6u71 and 7u51 fixes an unspecified vulnerability in the Install component (CVE-2013-5906). Upstream has CVSSv2 scored this issue as: 5.1/AV:N/AC:H/Au:N/C:P/I:P/A:P
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html#AppendixJAVA
Oracle Java SE 6u71 and 7u51 fixes an unspecified vulnerability in the Deployment component (CVE-2013-5888). Upstream has CVSSv2 scored this issue as: 4.6/AV:L/AC:L/Au:N/C:P/I:P/A:P
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html#AppendixJAVA
Oracle Java SE 6u71 and 7u51 fixes an unspecified vulnerability in the Deployment component (CVE-2013-5887). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:N/I:N/A:P
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html#AppendixJAVA
Oracle Java SE 6u71 and 7u51 fixes an unspecified vulnerability in the Deployment component (CVE-2013-5898). Upstream has CVSSv2 scored this issue as: 4.0/AV:N/AC:H/Au:N/C:P/I:P/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html#AppendixJAVA
Oracle Java SE 6u71 and 7u51 fixes an unspecified vulnerability in the Deployment component (CVE-2013-5902). Upstream has CVSSv2 scored this issue as: 5.1/AV:N/AC:H/Au:N/C:P/I:P/A:P
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html#AppendixJAVA
Oracle Java SE 6u71 and 7u51 fixes an unspecified vulnerability in the Deployment component (CVE-2013-5899). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html#AppendixJAVA
It was discovered that the CORBA stub factories did not properly check code permissions. An untrusted Java application or applet could possibly use this flaw to bypass certain Java sandbox restrictions.