Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

SUSE Linux 11 SP2: 2013:0434-1 Critical: Java Remote Execution

suse
Calendar Grey March 12, 2013
Scroller Suse
SUSE Security Patch addresses severe flaws in Java impacting SUSE Linux systems. Information regarding execution and memory overflow vulnerabilities.
An update that fixes two vulnerabilities is now available

Summary

This release of Icedtea6-1.12.4 fixes the following two issues that allowed a remote attacker to execute arbitrary code remotely by providing crafted images to the affected code. * CVE-2013-0809: CVSS v2 Base Score: 6.8 (critical) (AV:N/AC:M/Au:N/C:P/I:P/A:P): Insufficient Information (CWE-noinfo) * CVE-2013-1493: CVSS v2 Base Score: 6.8 (critical) (AV:N/AC:M/Au:N/C:P/I:P/A:P): Buffer Errors (CWE-119) Security Issue references: * CVE-2013-0809 * CVE-2013-1493 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Desktop 11 SP2:

References

#807487

Cross- CVE-2013-0809 CVE-2013-1493

Affected Products:

SUSE Linux Enterprise Desktop 11 SP2

https://www.suse.com/security/cve/CVE-2013-0809.html

https://www.suse.com/security/cve/CVE-2013-1493.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2013:0434-1
Rating: critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.