CVE-2013-0431

Publication date 31 January 2013

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

5.3 · Medium

Score breakdown

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka “Issue 52,” a different vulnerability than CVE-2013-1490.

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
openjdk-7 12.10 quantal
Fixed 7u13-2.3.6-0ubuntu0.12.10.1
12.04 LTS precise
Fixed 7u13-2.3.6-0ubuntu0.12.04.1
11.10 oneiric
Fixed 7u13-2.3.6-0ubuntu0.11.10.2
10.04 LTS lucid Not in release
8.04 LTS hardy Not in release

Notes


mdeslaur

in lucid+, NetX and the plugin moved to the icedtea-web package


jdstrand

openjdk-6b18 FTBFS on 11.04 (LP: #1043003) no fix available as of 2013-02-14

Severity score breakdown

Parameter Value
Base score 5.3 · Medium
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality Low
Integrity impact None
Availability impact None
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N