Vulnerability & Exploit Database

Back to search

Apple Java security update for CVE-2013-0443

Severity CVSS Published Added Modified
4 (AV:N/AC:H/Au:N/C:P/I:P/A:N) February 01, 2013 February 03, 2013 December 12, 2013

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect validation of Diffie-Hellman keys, which allows remote attackers to conduct a "small subgroup attack" to force the use of weak session keys or obtain sensitive information about the private key.

Scan For This Vulnerability

Use our top-rated tool to discover, prioritize, and remediate your vulnerabilities

 Free InsightVM Trial

References

Solution Reference

Java Security Update

Solution

apple-java-upgrade-1_6_0_41

Related Vulnerabilities