CVE
- Id
- 60387
- CVE No.
- CVE-2013-0440
- Status
- Candidate
- Description
- Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 7, allows remote attackers to affect availability via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to CPU consumption in the the SSL/TLS implementation via a large number of ClientHello packets that are not properly handled by (1) ClientHandshaker.java and (2) ServerHandshaker.java.
- Phase
- Assigned (20121207)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
609551 | 60387 | CVE-2013-0440 | CONFIRM:http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html | View |
609552 | 60387 | CVE-2013-0440 | CONFIRM:http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS | View |
609553 | 60387 | CVE-2013-0440 | CONFIRM:http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/5c1e8b779c65 | View |
609554 | 60387 | CVE-2013-0440 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=859140 | View |
609555 | 60387 | CVE-2013-0440 | CONFIRM:https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056 | View |
609556 | 60387 | CVE-2013-0440 | GENTOO:GLSA-201406-32 | View |
609557 | 60387 | CVE-2013-0440 | URL:http://security.gentoo.org/glsa/glsa-201406-32.xml | View |
609558 | 60387 | CVE-2013-0440 | HP:HPSBUX02864 | View |
609559 | 60387 | CVE-2013-0440 | URL:http://marc.info/?l=bugtraq&m=136570436423916&w=2 | View |
609560 | 60387 | CVE-2013-0440 | HP:SSRT101156 | View |
609561 | 60387 | CVE-2013-0440 | URL:http://marc.info/?l=bugtraq&m=136570436423916&w=2 | View |
609562 | 60387 | CVE-2013-0440 | HP:HPSBMU02874 | View |
609563 | 60387 | CVE-2013-0440 | URL:http://marc.info/?l=bugtraq&m=136733161405818&w=2 | View |
609564 | 60387 | CVE-2013-0440 | HP:HPSBUX02857 | View |
609565 | 60387 | CVE-2013-0440 | URL:http://marc.info/?l=bugtraq&m=136439120408139&w=2 | View |
609566 | 60387 | CVE-2013-0440 | HP:SSRT101103 | View |
609567 | 60387 | CVE-2013-0440 | URL:http://marc.info/?l=bugtraq&m=136439120408139&w=2 | View |
609568 | 60387 | CVE-2013-0440 | HP:SSRT101184 | View |
609569 | 60387 | CVE-2013-0440 | URL:http://marc.info/?l=bugtraq&m=136733161405818&w=2 | View |
609570 | 60387 | CVE-2013-0440 | MANDRIVA:MDVSA-2013:095 | View |
609571 | 60387 | CVE-2013-0440 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2013:095 | View |
609572 | 60387 | CVE-2013-0440 | REDHAT:RHSA-2013:0236 | View |
609573 | 60387 | CVE-2013-0440 | URL:http://rhn.redhat.com/errata/RHSA-2013-0236.html | View |
609574 | 60387 | CVE-2013-0440 | REDHAT:RHSA-2013:0237 | View |
609575 | 60387 | CVE-2013-0440 | URL:http://rhn.redhat.com/errata/RHSA-2013-0237.html | View |
609576 | 60387 | CVE-2013-0440 | REDHAT:RHSA-2013:0245 | View |
609577 | 60387 | CVE-2013-0440 | URL:http://rhn.redhat.com/errata/RHSA-2013-0245.html | View |
609578 | 60387 | CVE-2013-0440 | REDHAT:RHSA-2013:0246 | View |
609579 | 60387 | CVE-2013-0440 | URL:http://rhn.redhat.com/errata/RHSA-2013-0246.html | View |
609580 | 60387 | CVE-2013-0440 | REDHAT:RHSA-2013:0247 | View |
609581 | 60387 | CVE-2013-0440 | URL:http://rhn.redhat.com/errata/RHSA-2013-0247.html | View |
609582 | 60387 | CVE-2013-0440 | REDHAT:RHSA-2013:1455 | View |
609583 | 60387 | CVE-2013-0440 | URL:http://rhn.redhat.com/errata/RHSA-2013-1455.html | View |
609584 | 60387 | CVE-2013-0440 | REDHAT:RHSA-2013:1456 | View |
609585 | 60387 | CVE-2013-0440 | URL:http://rhn.redhat.com/errata/RHSA-2013-1456.html | View |
609586 | 60387 | CVE-2013-0440 | SUSE:openSUSE-SU-2013:0312 | View |
609587 | 60387 | CVE-2013-0440 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html | View |
609588 | 60387 | CVE-2013-0440 | SUSE:openSUSE-SU-2013:0377 | View |
609589 | 60387 | CVE-2013-0440 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html | View |
609590 | 60387 | CVE-2013-0440 | SUSE:SUSE-SU-2013:0478 | View |
609591 | 60387 | CVE-2013-0440 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.html | View |
609592 | 60387 | CVE-2013-0440 | CERT:TA13-032A | View |
609593 | 60387 | CVE-2013-0440 | URL:http://www.us-cert.gov/cas/techalerts/TA13-032A.html | View |
609594 | 60387 | CVE-2013-0440 | CERT-VN:VU#858729 | View |
609595 | 60387 | CVE-2013-0440 | URL:http://www.kb.cert.org/vuls/id/858729 | View |
609596 | 60387 | CVE-2013-0440 | BID:57712 | View |
609597 | 60387 | CVE-2013-0440 | URL:http://www.securityfocus.com/bid/57712 | View |
609598 | 60387 | CVE-2013-0440 | OVAL:oval:org.mitre.oval:def:16558 | View |
609599 | 60387 | CVE-2013-0440 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:16558 | View |
609600 | 60387 | CVE-2013-0440 | OVAL:oval:org.mitre.oval:def:19229 | View |
609601 | 60387 | CVE-2013-0440 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:19229 | View |
609602 | 60387 | CVE-2013-0440 | OVAL:oval:org.mitre.oval:def:19285 | View |
609603 | 60387 | CVE-2013-0440 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:19285 | View |
609604 | 60387 | CVE-2013-0440 | OVAL:oval:org.mitre.oval:def:19397 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
19813 | JVNDB-2013-001388 | Oracle Java SE の Java Runtime Environment における AWT の処理に関する脆弱性 | Oracle Java SE の Java Runtime Environment (JRE) には、AWT に関する処理に不備があるため、機密性、完全性、可用性に影響のある脆弱性が存在します。 | CVE-2013-0445 | 60387 | 10 | http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-001388.html | View |