CVE Vulnerabilities

CVE-2013-0443

Published: Feb 02, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect validation of Diffie-Hellman keys, which allows remote attackers to conduct a small subgroup attack to force the use of weak session keys or obtain sensitive information about the private key.

Affected Software

NameVendorStart VersionEnd Version
JreOracle1.7.0 (including)1.7.0 (including)
JreOracle1.7.0-update1 (including)1.7.0-update1 (including)
JreOracle1.7.0-update10 (including)1.7.0-update10 (including)
JreOracle1.7.0-update11 (including)1.7.0-update11 (including)
JreOracle1.7.0-update2 (including)1.7.0-update2 (including)
JreOracle1.7.0-update3 (including)1.7.0-update3 (including)
JreOracle1.7.0-update4 (including)1.7.0-update4 (including)
JreOracle1.7.0-update5 (including)1.7.0-update5 (including)
JreOracle1.7.0-update6 (including)1.7.0-update6 (including)
JreOracle1.7.0-update7 (including)1.7.0-update7 (including)
JreOracle1.7.0-update9 (including)1.7.0-update9 (including)
Red Hat Enterprise Linux 5RedHatjava-1.6.0-openjdk-1:1.6.0.0-1.33.1.11.6.el5_9*
Red Hat Enterprise Linux 5RedHatjava-1.7.0-openjdk-1:1.7.0.9-2.3.5.3.el5_9*
Red Hat Enterprise Linux 6RedHatjava-1.6.0-openjdk-1:1.6.0.0-1.54.1.11.6.el6_3*
Red Hat Enterprise Linux 6RedHatjava-1.7.0-openjdk-1:1.7.0.9-2.3.5.3.el6_3*
Red Hat Network Satellite Server v 5.4RedHatjava-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el6_4*
Red Hat Network Satellite Server v 5.5RedHatjava-1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el6_4*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.6.0-sun-1:1.6.0.39-1jpp.4.el5_9*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.7.0-oracle-1:1.7.0.13-1jpp.1.el5_9*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.5.0-ibm-1:1.5.0.16.0-1jpp.1.el5_9*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.6.0-ibm-1:1.6.0.13.0-1jpp.2.el5_9*
Supplementary for Red Hat Enterprise Linux 5RedHatjava-1.7.0-ibm-1:1.7.0.4.0-1jpp.2.el5_9*
Supplementary for Red Hat Enterprise Linux 6RedHatjava-1.6.0-sun-1:1.6.0.39-1jpp.1.el6_3*
Supplementary for Red Hat Enterprise Linux 6RedHatjava-1.7.0-oracle-1:1.7.0.13-1jpp.3.el6_3*
Supplementary for Red Hat Enterprise Linux 6RedHatjava-1.5.0-ibm-1:1.5.0.16.0-1jpp.1.el6_4*
Supplementary for Red Hat Enterprise Linux 6RedHatjava-1.6.0-ibm-1:1.6.0.13.0-1jpp.3.el6_4*
Supplementary for Red Hat Enterprise Linux 6RedHatjava-1.7.0-ibm-1:1.7.0.4.0-1jpp.2.el6_4*
Openjdk-6Ubuntudevel*
Openjdk-6Ubuntuhardy*
Openjdk-6Ubuntulucid*
Openjdk-6Ubuntuoneiric*
Openjdk-6Ubuntuprecise*
Openjdk-6Ubuntuquantal*
Openjdk-6Ubuntuupstream*
Openjdk-6b18Ubuntulucid*
Openjdk-6b18Ubuntuoneiric*
Openjdk-7Ubuntudevel*
Openjdk-7Ubuntuoneiric*
Openjdk-7Ubuntuprecise*
Openjdk-7Ubuntuquantal*
Openjdk-7Ubuntuupstream*
Sun-java5Ubuntuhardy*
Sun-java5Ubuntuupstream*
Sun-java6Ubuntuhardy*

References