PublicDateAtUSN: 2013-02-01 Candidate: CVE-2013-0448 PublicDate: 2013-02-02 00:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0448 http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021708.html http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-February/021728.html https://ubuntu.com/security/notices/USN-1724-1 Description: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 allows remote attackers to affect integrity via unknown vectors related to Libraries. Ubuntu-Description: Notes: jdstrand> http://rhn.redhat.com/errata/RHSA-2013-0237.html states this is Oracle JDK only, but based on Oracle advisory we claimed it was fixed in https://ubuntu.com/security/notices/USN-1724-1. Bugs: Priority: medium Discovered-by: Assigned-to: doko CVSS: upstream_openjdk-7: pending (7u9-2.3.5) hardy_openjdk-7: DNE lucid_openjdk-7: DNE oneiric_openjdk-7: released (7u13-2.3.6-0ubuntu0.11.10.2) precise_openjdk-7: released (7u13-2.3.6-0ubuntu0.12.04.1) quantal_openjdk-7: released (7u13-2.3.6-0ubuntu0.12.10.1) devel_openjdk-7: released (7u13-2.3.6-1ubuntu1)