SuSE: 2013:0434-1: critical: Java
Summary
This release of Icedtea6-1.12.4 fixes the following two
issues that allowed a remote attacker to execute arbitrary
code remotely by providing crafted images to the affected
code.
* CVE-2013-0809: CVSS v2 Base Score: 6.8 (critical)
(AV:N/AC:M/Au:N/C:P/I:P/A:P): Insufficient Information
(CWE-noinfo)
* CVE-2013-1493: CVSS v2 Base Score: 6.8 (critical)
(AV:N/AC:M/Au:N/C:P/I:P/A:P): Buffer Errors (CWE-119)
Security Issue references:
* CVE-2013-0809
References
#807487
Cross- CVE-2013-0809 CVE-2013-1493
Affected Products:
SUSE Linux Enterprise Desktop 11 SP2
https://www.suse.com/security/cve/CVE-2013-0809.html
https://www.suse.com/security/cve/CVE-2013-1493.html
https://bugzilla.novell.com/807487
https://login.microfocus.com/nidp/app/login