SuSE 11.2 Security Update : Java (SAT Patch Number 7457)

Critical Nessus Plugin ID 65245


The remote SuSE 11 host is missing one or more security updates.


This release of Icedtea6-1.12.4 fixes the following two issues that allowed a remote attacker to execute arbitrary code remotely by providing crafted images to the affected code.

- CVE-2013-0809: CVSS v2 Base Score: 6.8 (critical) (AV:N/AC:M/Au:N/C:P/I:P/A:P): Insufficient Information (CWE-noinfo)

- CVE-2013-1493: CVSS v2 Base Score: 6.8 (critical) (AV:N/AC:M/Au:N/C:P/I:P/A:P): Buffer Errors (CWE-119)


Apply SAT patch number 7457.

See Also

Plugin Details

Severity: Critical

ID: 65245

File Name: suse_11_java-1_6_0-openjdk-130307.nasl

Version: $Revision: 1.10 $

Type: local

Agent: unix

Published: 2013/03/13

Modified: 2016/12/21

Dependencies: 12634

Risk Information

Risk Factor: Critical


Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:11:java-1_6_0-openjdk, p-cpe:/a:novell:suse_linux:11:java-1_6_0-openjdk-demo, p-cpe:/a:novell:suse_linux:11:java-1_6_0-openjdk-devel, cpe:/o:novell:suse_linux:11

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2013/03/07

Exploitable With

Core Impact

Metasploit (Java CMM Remote Code Execution)

Reference Information

CVE: CVE-2013-0809, CVE-2013-1493

CWE: 119