CVE-2013-0431
Publication date 31 January 2013
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka “Issue 52,” a different vulnerability than CVE-2013-1490.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| openjdk-7 | 12.10 quantal |
Fixed 7u13-2.3.6-0ubuntu0.12.10.1
|
| 12.04 LTS precise |
Fixed 7u13-2.3.6-0ubuntu0.12.04.1
|
|
| 11.10 oneiric |
Fixed 7u13-2.3.6-0ubuntu0.11.10.2
|
|
| 10.04 LTS lucid | Not in release | |
| 8.04 LTS hardy | Not in release |
Notes
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Network |
| Attack complexity | Low |
| Privileges required | None |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | Low |
| Integrity impact | None |
| Availability impact | None |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
References
Other references
- http://www.informationweek.com/security/application-security/java-hacker-uncovers-two-flaws-in-latest/240146717
- http://seclists.org/fulldisclosure/2013/Jan/195
- http://seclists.org/fulldisclosure/2013/Jan/142
- http://blogs.computerworld.com/malware-and-vulnerabilities/21693/yet-another-java-security-flaw-discovered-number-53
- http://arstechnica.com/security/2013/01/critical-java-vulnerabilies-confirmed-in-latest-version/
- http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
- https://www.cve.org/CVERecord?id=CVE-2013-0431
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog