Alpine: openjdk6: security update to 6.-r0 (deprecated)

high Tenable Self-Hosted Container Security Plugin ID 401264

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and
earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality,
integrity, and availability via unknown vectors related to Libraries, a different vulnerability than
CVE-2013-5850. (CVE-2013-5842)

- Unspecified vulnerability in the Java SE, Java SE Embedded component in Oracle Java SE Java SE 7u40 and
earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier
allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.
(CVE-2013-3829)

- XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE)
in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well
as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8
and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products
allows remote attackers to cause a denial of service via vectors related to XML attribute names.
(CVE-2013-4002)

- Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u40 and earlier and Java SE
6u60 and earlier allows remote attackers to affect integrity via unknown vectors related to jhat.
(CVE-2013-5772)

- Unspecified vulnerability in Oracle Java SE 7u40 and earlier, 6u60 and earlier, 5.0u51 and earlier, and
Embedded 7u40 and earlier allows remote attackers to affect integrity via unknown vectors related to
Libraries. (CVE-2013-5774)

See Also

https://git.alpinelinux.org/aports/commit/?id=5e6534d32ba41c56a31e1cb74c912f181b825100

https://git.alpinelinux.org/aports/commit/?id=a8d3f77003ae46f6268c0c35baadeed971865a82

Plugin Details

Severity: High

ID: 401264

Version: Revision 1.25

Type: Local

Published: 8/16/2023

Updated: 1/17/2024

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.0

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2013-5842

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2013-5829

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 11/27/2013

Vulnerability Publication Date: 7/17/2013

Reference Information

CVE: CVE-2013-3829, CVE-2013-4002, CVE-2013-5772, CVE-2013-5774, CVE-2013-5778, CVE-2013-5780, CVE-2013-5782, CVE-2013-5783, CVE-2013-5784, CVE-2013-5790, CVE-2013-5797, CVE-2013-5802, CVE-2013-5803, CVE-2013-5804, CVE-2013-5809, CVE-2013-5814, CVE-2013-5817, CVE-2013-5820, CVE-2013-5823, CVE-2013-5825, CVE-2013-5829, CVE-2013-5830, CVE-2013-5840, CVE-2013-5842, CVE-2013-5849, CVE-2013-5850, CVE-2013-5851

BID: 61310, 63082, 63089, 63095, 63098, 63101, 63102, 63103, 63106, 63110, 63115, 63118, 63120, 63121, 63128, 63133, 63134, 63135, 63137, 63142, 63143, 63146, 63148, 63149, 63150, 63153, 63154