CVE
- Id
- 60390
- CVE No.
- CVE-2013-0443
- Status
- Candidate
- Description
- Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect validation of Diffie-Hellman keys, which allows remote attackers to conduct a "small subgroup attack" to force the use of weak session keys or obtain sensitive information about the private key.
- Phase
- Assigned (20121207)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
609709 | 60390 | CVE-2013-0443 | CONFIRM:http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html | View |
609710 | 60390 | CVE-2013-0443 | CONFIRM:http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS | View |
609711 | 60390 | CVE-2013-0443 | CONFIRM:http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/496bced2d275 | View |
609712 | 60390 | CVE-2013-0443 | CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=907340 | View |
609713 | 60390 | CVE-2013-0443 | CONFIRM:https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056 | View |
609714 | 60390 | CVE-2013-0443 | GENTOO:GLSA-201406-32 | View |
609715 | 60390 | CVE-2013-0443 | URL:http://security.gentoo.org/glsa/glsa-201406-32.xml | View |
609716 | 60390 | CVE-2013-0443 | HP:HPSBUX02864 | View |
609717 | 60390 | CVE-2013-0443 | URL:http://marc.info/?l=bugtraq&m=136570436423916&w=2 | View |
609718 | 60390 | CVE-2013-0443 | HP:SSRT101156 | View |
609719 | 60390 | CVE-2013-0443 | URL:http://marc.info/?l=bugtraq&m=136570436423916&w=2 | View |
609720 | 60390 | CVE-2013-0443 | HP:HPSBMU02874 | View |
609721 | 60390 | CVE-2013-0443 | URL:http://marc.info/?l=bugtraq&m=136733161405818&w=2 | View |
609722 | 60390 | CVE-2013-0443 | HP:HPSBUX02857 | View |
609723 | 60390 | CVE-2013-0443 | URL:http://marc.info/?l=bugtraq&m=136439120408139&w=2 | View |
609724 | 60390 | CVE-2013-0443 | HP:SSRT101103 | View |
609725 | 60390 | CVE-2013-0443 | URL:http://marc.info/?l=bugtraq&m=136439120408139&w=2 | View |
609726 | 60390 | CVE-2013-0443 | HP:SSRT101184 | View |
609727 | 60390 | CVE-2013-0443 | URL:http://marc.info/?l=bugtraq&m=136733161405818&w=2 | View |
609728 | 60390 | CVE-2013-0443 | MANDRIVA:MDVSA-2013:095 | View |
609729 | 60390 | CVE-2013-0443 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2013:095 | View |
609730 | 60390 | CVE-2013-0443 | REDHAT:RHSA-2013:0236 | View |
609731 | 60390 | CVE-2013-0443 | URL:http://rhn.redhat.com/errata/RHSA-2013-0236.html | View |
609732 | 60390 | CVE-2013-0443 | REDHAT:RHSA-2013:0237 | View |
609733 | 60390 | CVE-2013-0443 | URL:http://rhn.redhat.com/errata/RHSA-2013-0237.html | View |
609734 | 60390 | CVE-2013-0443 | REDHAT:RHSA-2013:0245 | View |
609735 | 60390 | CVE-2013-0443 | URL:http://rhn.redhat.com/errata/RHSA-2013-0245.html | View |
609736 | 60390 | CVE-2013-0443 | REDHAT:RHSA-2013:0246 | View |
609737 | 60390 | CVE-2013-0443 | URL:http://rhn.redhat.com/errata/RHSA-2013-0246.html | View |
609738 | 60390 | CVE-2013-0443 | REDHAT:RHSA-2013:0247 | View |
609739 | 60390 | CVE-2013-0443 | URL:http://rhn.redhat.com/errata/RHSA-2013-0247.html | View |
609740 | 60390 | CVE-2013-0443 | REDHAT:RHSA-2013:1455 | View |
609741 | 60390 | CVE-2013-0443 | URL:http://rhn.redhat.com/errata/RHSA-2013-1455.html | View |
609742 | 60390 | CVE-2013-0443 | REDHAT:RHSA-2013:1456 | View |
609743 | 60390 | CVE-2013-0443 | URL:http://rhn.redhat.com/errata/RHSA-2013-1456.html | View |
609744 | 60390 | CVE-2013-0443 | SUSE:openSUSE-SU-2013:0312 | View |
609745 | 60390 | CVE-2013-0443 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00014.html | View |
609746 | 60390 | CVE-2013-0443 | SUSE:openSUSE-SU-2013:0377 | View |
609747 | 60390 | CVE-2013-0443 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html | View |
609748 | 60390 | CVE-2013-0443 | SUSE:SUSE-SU-2013:0478 | View |
609749 | 60390 | CVE-2013-0443 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.html | View |
609750 | 60390 | CVE-2013-0443 | CERT:TA13-032A | View |
609751 | 60390 | CVE-2013-0443 | URL:http://www.us-cert.gov/cas/techalerts/TA13-032A.html | View |
609752 | 60390 | CVE-2013-0443 | CERT-VN:VU#858729 | View |
609753 | 60390 | CVE-2013-0443 | URL:http://www.kb.cert.org/vuls/id/858729 | View |
609754 | 60390 | CVE-2013-0443 | OVAL:oval:org.mitre.oval:def:15832 | View |
609755 | 60390 | CVE-2013-0443 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:15832 | View |
609756 | 60390 | CVE-2013-0443 | OVAL:oval:org.mitre.oval:def:19010 | View |
609757 | 60390 | CVE-2013-0443 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:19010 | View |
609758 | 60390 | CVE-2013-0443 | OVAL:oval:org.mitre.oval:def:19382 | View |
609759 | 60390 | CVE-2013-0443 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:19382 | View |
609760 | 60390 | CVE-2013-0443 | OVAL:oval:org.mitre.oval:def:19437 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
19821 | JVNDB-2013-001396 | Oracle Java SE の Java Runtime Environment におけるライブラリの処理に関する脆弱性 | Oracle Java SE の Java Runtime Environment (JRE) には、ライブラリに関する処理に不備があるため、完全性に影響のある脆弱性が存在します。 | CVE-2013-0448 | 60390 | 5 | http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-001396.html | View |