<?xml version="1.0" encoding="utf-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Red Hat Security Advisory: java-1.6.0-openjdk security update</DocumentTitle>
  <DocumentType>Security Advisory</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>secalert@redhat.com</ContactDetails>
    <IssuingAuthority>Red Hat Security Response Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification><ID>RHSA-2013:0245</ID></Identification>
    <Status>Final</Status>
    <Version>2</Version>
    <RevisionHistory>
       <Revision>
         <Number>2</Number>
         <Date>2013-02-08T18:50:00Z</Date>
         <Description>Current version</Description>
       </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2013-02-08T18:50:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2013-02-08T18:50:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>Red Hat rhsa-to-cvrf 1.0.1484</Engine>
      <Date>2013-02-08T19:37:02Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">
Updated java-1.6.0-openjdk packages that fix several security issues are
now available for Red Hat Enterprise Linux 6.

The Red Hat Security Response Team has rated this update as having critical
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.    </Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit.

Multiple improper permission check issues were discovered in the AWT,
CORBA, JMX, and Libraries components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass Java sandbox
restrictions. (CVE-2013-0442, CVE-2013-0445, CVE-2013-0441, CVE-2013-1475,
CVE-2013-1476, CVE-2013-0429, CVE-2013-0450, CVE-2013-0425, CVE-2013-0426,
CVE-2013-0428)

Multiple flaws were found in the way image parsers in the 2D and AWT
components handled image raster parameters. A specially-crafted image could
cause Java Virtual Machine memory corruption and, possibly, lead to
arbitrary code execution with the virtual machine privileges.
(CVE-2013-1478, CVE-2013-1480)

A flaw was found in the AWT component's clipboard handling code. An
untrusted Java application or applet could use this flaw to access
clipboard data, bypassing Java sandbox restrictions. (CVE-2013-0432)

The default Java security properties configuration did not restrict access
to certain com.sun.xml.internal packages. An untrusted Java application or
applet could use this flaw to access information, bypassing certain Java
sandbox restrictions. This update lists the whole package as restricted.
(CVE-2013-0435)

Multiple improper permission check issues were discovered in the Libraries,
Networking, and JAXP components. An untrusted Java application or applet
could use these flaws to bypass certain Java sandbox restrictions.
(CVE-2013-0427, CVE-2013-0433, CVE-2013-0434)

It was discovered that the RMI component's CGIHandler class used user
inputs in error messages without any sanitization. An attacker could use
this flaw to perform a cross-site scripting (XSS) attack. (CVE-2013-0424)

It was discovered that the SSL/TLS implementation in the JSSE component
did not properly enforce handshake message ordering, allowing an unlimited
number of handshake restarts. A remote attacker could use this flaw to
make an SSL/TLS server using JSSE consume an excessive amount of CPU by
continuously restarting the handshake. (CVE-2013-0440)

It was discovered that the JSSE component did not properly validate
Diffie-Hellman public keys. An SSL/TLS client could possibly use this flaw
to perform a small subgroup attack. (CVE-2013-0443)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

This erratum also upgrades the OpenJDK package to IcedTea6 1.11.6. Refer to
the NEWS file, linked to in the References, for further information.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.    </Note>
    <Note Title="Terms of Use" Ordinal="3" Type="Legal Disclaimer" xml:lang="en">Please see https://www.redhat.com/footer/terms-of-use.html</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright © 2013 Red Hat, Inc. All rights reserved.</DocumentDistribution>
  <AggregateSeverity Namespace="https://access.redhat.com/security/updates/classification/">Critical</AggregateSeverity>
  <DocumentReferences>
    <Reference Type="Self">
       <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL>
       <Description>https://rhn.redhat.com/errata/RHSA-2013-0245.html</Description>
    </Reference>
    <Reference>
       <URL>https://access.redhat.com/security/updates/classification/#critical</URL>
       <Description>https://access.redhat.com/security/updates/classification/#critical</Description>
    </Reference>
    <Reference>
       <URL>http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</URL>
       <Description>http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Red Hat Enterprise Linux">
      <Branch Type="Product Name" Name="Red Hat Enterprise Linux HPC Node Optional (v. 6)">
        <FullProductName ProductID="6ComputeNode-optional-6.3.z">Red Hat Enterprise Linux HPC Node Optional (v. 6)</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="Red Hat Enterprise Linux Server (v. 6)">
        <FullProductName ProductID="6Server-6.3.z">Red Hat Enterprise Linux Server (v. 6)</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="Red Hat Enterprise Linux Workstation (v. 6)">
        <FullProductName ProductID="6Workstation-6.3.z">Red Hat Enterprise Linux Workstation (v. 6)</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="Red Hat Enterprise Linux Desktop Optional (v. 6)">
        <FullProductName ProductID="6Client-optional-6.3.z">Red Hat Enterprise Linux Desktop Optional (v. 6)</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="Red Hat Enterprise Linux Workstation Optional (v. 6)">
        <FullProductName ProductID="6Workstation-optional-6.3.z">Red Hat Enterprise Linux Workstation Optional (v. 6)</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="Red Hat Enterprise Linux HPC Node (v. 6)">
        <FullProductName ProductID="6ComputeNode-6.3.z">Red Hat Enterprise Linux HPC Node (v. 6)</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="Red Hat Enterprise Linux Desktop (v. 6)">
        <FullProductName ProductID="6Client-6.3.z">Red Hat Enterprise Linux Desktop (v. 6)</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="Red Hat Enterprise Linux Server Optional (v. 6)">
        <FullProductName ProductID="6Server-optional-6.3.z">Red Hat Enterprise Linux Server Optional (v. 6)</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3">
      <FullProductName ProductID="java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3">java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3.src.rpm</FullProductName>
    </Branch>
    <Relationship ProductReference="java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3" RelationType="Default Component Of" RelatesToProductReference="6ComputeNode-optional-6.3.z">
      <FullProductName ProductID="6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3">java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3 as a component of Red Hat Enterprise Linux HPC Node Optional (v. 6)</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3" RelationType="Default Component Of" RelatesToProductReference="6Server-6.3.z">
      <FullProductName ProductID="6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3">java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3 as a component of Red Hat Enterprise Linux Server (v. 6)</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3" RelationType="Default Component Of" RelatesToProductReference="6Workstation-6.3.z">
      <FullProductName ProductID="6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3">java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3 as a component of Red Hat Enterprise Linux Workstation (v. 6)</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3" RelationType="Default Component Of" RelatesToProductReference="6Client-optional-6.3.z">
      <FullProductName ProductID="6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3">java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3 as a component of Red Hat Enterprise Linux Desktop Optional (v. 6)</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3" RelationType="Default Component Of" RelatesToProductReference="6Workstation-optional-6.3.z">
      <FullProductName ProductID="6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3">java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3 as a component of Red Hat Enterprise Linux Workstation Optional (v. 6)</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3" RelationType="Default Component Of" RelatesToProductReference="6ComputeNode-6.3.z">
      <FullProductName ProductID="6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3">java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3 as a component of Red Hat Enterprise Linux HPC Node (v. 6)</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3" RelationType="Default Component Of" RelatesToProductReference="6Client-6.3.z">
      <FullProductName ProductID="6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3">java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3 as a component of Red Hat Enterprise Linux Desktop (v. 6)</FullProductName>
    </Relationship>
    <Relationship ProductReference="java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3" RelationType="Default Component Of" RelatesToProductReference="6Server-optional-6.3.z">
      <FullProductName ProductID="6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3">java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3 as a component of Red Hat Enterprise Linux Server Optional (v. 6)</FullProductName>
    </Relationship>
  </ProductTree>

  <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">It was discovered that the RMI component's CGIHandler class used user inputs in error messages without any sanitization. An attacker could use this flaw to perform a cross-site scripting (XSS) attack. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0424</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Moderate</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.3</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0424.html</URL>
        <Description>CVE-2013-0424</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=906813</URL>
        <Description>bz#906813: CVE-2013-0424 OpenJDK: RMI CGIHandler XSS issue (RMI, 6563318)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple improper permission check issues were discovered in the AWT, CORBA, JMX, and Libraries components in OpenJDK. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0425</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Critical</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>6.8</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0425.html</URL>
        <Description>CVE-2013-0425</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=907344</URL>
        <Description>bz#907344: CVE-2013-0425 OpenJDK: logging insufficient access control checks (Libraries, 6664509)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple improper permission check issues were discovered in the AWT, CORBA, JMX, and Libraries components in OpenJDK. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0426</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Critical</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>6.8</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0426.html</URL>
        <Description>CVE-2013-0426</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=907346</URL>
        <Description>bz#907346: CVE-2013-0426 OpenJDK: logging insufficient access control checks (Libraries, 6664528)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple improper permission check issues were discovered in the Libraries, Networking, and JAXP components. An untrusted Java application or applet could use these flaws to bypass certain Java sandbox restrictions. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0427</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Moderate</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.3</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0427.html</URL>
        <Description>CVE-2013-0427</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=907455</URL>
        <Description>bz#907455: CVE-2013-0427 OpenJDK: invalid threads subject to interrupts (Libraries, 6776941)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple improper permission check issues were discovered in the AWT, CORBA, JMX, and Libraries components in OpenJDK. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0428</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Critical</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>6.8</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0428.html</URL>
        <Description>CVE-2013-0428</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=907207</URL>
        <Description>bz#907207: CVE-2013-0428 OpenJDK: reflection API incorrect checks for proxy classes (Libraries, 7197546, SE-2012-01 Issue 29)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple improper permission check issues were discovered in the AWT, CORBA, JMX, and Libraries components in OpenJDK. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0429</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Important</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>5.1</BaseScore>
      <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0429.html</URL>
        <Description>CVE-2013-0429</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=907460</URL>
        <Description>bz#907460: CVE-2013-0429 OpenJDK: PresentationManager incorrectly shared (CORBA, 7141694)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the AWT component's clipboard handling code. An untrusted Java application or applet could use this flaw to access clipboard data, bypassing Java sandbox restrictions. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0432</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Moderate</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>5.8</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0432.html</URL>
        <Description>CVE-2013-0432</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=907219</URL>
        <Description>bz#907219: CVE-2013-0432 OpenJDK: insufficient clipboard access premission checks (AWT, 7186952)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple improper permission check issues were discovered in the Libraries, Networking, and JAXP components. An untrusted Java application or applet could use these flaws to bypass certain Java sandbox restrictions. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0433</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Moderate</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.3</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0433.html</URL>
        <Description>CVE-2013-0433</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=907456</URL>
        <Description>bz#907456: CVE-2013-0433 OpenJDK: InetSocketAddress serialization issue (Networking, 7201071)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple improper permission check issues were discovered in the Libraries, Networking, and JAXP components. An untrusted Java application or applet could use these flaws to bypass certain Java sandbox restrictions. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0434</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Moderate</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.3</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0434.html</URL>
        <Description>CVE-2013-0434</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=907453</URL>
        <Description>bz#907453: CVE-2013-0434 OpenJDK: loadPropertyFile missing restrictions (JAXP, 8001235)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The default Java security properties configuration did not restrict access to certain com.sun.xml.internal packages. An untrusted Java application or applet could use this flaw to access information, bypassing certain Java sandbox restrictions. This update lists the whole package as restricted. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0435</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Moderate</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.3</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0435.html</URL>
        <Description>CVE-2013-0435</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=906892</URL>
        <Description>bz#906892: CVE-2013-0435 OpenJDK: com.sun.xml.internal.* not restricted packages (JAX-WS, 7201068)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">It was discovered that the SSL/TLS implementation in the JSSE component did not properly enforce handshake message ordering, allowing an unlimited number of handshake restarts. A remote attacker could use this flaw to make an SSL/TLS server using JSSE consume an excessive amount of CPU by continuously restarting the handshake. </Note></Notes>
    <DiscoveryDate>2012-07-25T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0440</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Moderate</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.3</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0440.html</URL>
        <Description>CVE-2013-0440</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=859140</URL>
        <Description>bz#859140: CVE-2013-0440 OpenJDK: CPU consumption DoS via repeated SSL ClientHello packets (JSSE, 7192393)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple improper permission check issues were discovered in the AWT, CORBA, JMX, and Libraries components in OpenJDK. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0441</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Critical</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>6.8</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0441.html</URL>
        <Description>CVE-2013-0441</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=907458</URL>
        <Description>bz#907458: CVE-2013-0441 OpenJDK: missing serialization restriction (CORBA, 7201066)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple improper permission check issues were discovered in the AWT, CORBA, JMX, and Libraries components in OpenJDK. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0442</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Critical</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>6.8</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0442.html</URL>
        <Description>CVE-2013-0442</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=906899</URL>
        <Description>bz#906899: CVE-2013-0442 OpenJDK: insufficient privilege checking issue (AWT, 7192977)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">It was discovered that the JSSE component did not properly validate Diffie-Hellman public keys. An SSL/TLS client could possibly use this flaw to perform a small subgroup attack. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0443</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Moderate</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.0</BaseScore>
      <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0443.html</URL>
        <Description>CVE-2013-0443</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=907340</URL>
        <Description>bz#907340: CVE-2013-0443 OpenJDK: insufficient Diffie-Hellman public key checks (JSSE, 7192392)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple improper permission check issues were discovered in the AWT, CORBA, JMX, and Libraries components in OpenJDK. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0445</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Critical</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>6.8</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0445.html</URL>
        <Description>CVE-2013-0445</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=906900</URL>
        <Description>bz#906900: CVE-2013-0445 OpenJDK: insufficient privilege checking issue (AWT, 8001057)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple improper permission check issues were discovered in the AWT, CORBA, JMX, and Libraries components in OpenJDK. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-0450</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Critical</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>6.8</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-0450.html</URL>
        <Description>CVE-2013-0450</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=906911</URL>
        <Description>bz#906911: CVE-2013-0450 OpenJDK: RequiredModelMBean missing access control context checks (JMX, 8000537)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple improper permission check issues were discovered in the AWT, CORBA, JMX, and Libraries components in OpenJDK. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. </Note></Notes>
    <DiscoveryDate>2012-09-26T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-09-25T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-1475</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Critical</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>6.8</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-1475.html</URL>
        <Description>CVE-2013-1475</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=860652</URL>
        <Description>bz#860652: CVE-2013-1475 OpenJDK: IIOP type reuse sandbox bypass (CORBA, 8000540, SE-2012-01 Issue 50)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple improper permission check issues were discovered in the AWT, CORBA, JMX, and Libraries components in OpenJDK. An untrusted Java application or applet could use these flaws to bypass Java sandbox restrictions. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-1476</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Critical</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>6.8</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-1476.html</URL>
        <Description>CVE-2013-1476</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=907457</URL>
        <Description>bz#907457: CVE-2013-1476 OpenJDK: missing ValueHandlerImpl class constructor access restriction (CORBA, 8000631)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple flaws were found in the way image parsers in the 2D and AWT components handled image raster parameters. A specially-crafted image could cause Java Virtual Machine memory corruption and, possibly, lead to arbitrary code execution with the virtual machine privileges. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-1478</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Critical</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>6.8</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-1478.html</URL>
        <Description>CVE-2013-1478</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=906894</URL>
        <Description>bz#906894: CVE-2013-1478 OpenJDK: image parser insufficient raster parameter checks (2D, 8001972)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple flaws were found in the way image parsers in the 2D and AWT components handled image raster parameters. A specially-crafted image could cause Java Virtual Machine memory corruption and, possibly, lead to arbitrary code execution with the virtual machine privileges. </Note></Notes>
    <DiscoveryDate>2013-02-01T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2013-02-01T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2013-1480</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Client-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Client-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6ComputeNode-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Server-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
      <ProductID>6Workstation-optional-6.3.z:java-1.6.0-openjdk-1.6.0.0-1.54.1.11.6.el6_3</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Critical</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>6.8</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2013-0245.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</URL>
        <Description>http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2013-1480.html</URL>
        <Description>CVE-2013-1480</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=906904</URL>
        <Description>bz#906904: CVE-2013-1480 OpenJDK: image parser insufficient raster parameter checks (AWT, 8002325)</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
