This article has been archived and is no longer updated by Apple.

About the security content of Java for OS X 2013-005 and Mac OS X v10.6 Update 17

This document describes the security content of Java for OS X 2013-005 and Mac OS X v10.6 Update 17.

This update can be downloaded and installed via Software Update preferences, or from Apple Downloads.

For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. To learn more about Apple Product Security, see the Apple Product Security website.

For information about the Apple Product Security PGP Key, see "How to use the Apple Product Security PGP Key."

Where possible, CVE IDs are used to reference the vulnerabilities for further information.

To learn about other Security Updates, see "Apple Security Updates".

Java for OS X 2013-005 and Mac OS X v10.6 Update 17

  • Java

Available for: Mac OS X v10.6.8, Mac OS X Server v10.6.8, OS X Lion v10.7 or later, OS X Lion Server v10.7 or later, OS X Mountain Lion 10.8 or later

Impact: Multiple vulnerabilities in Java 1.6.0_51

8011782

Description: Multiple vulnerabilities existed in Java 1.6.0_51, the most serious of which may allow an untrusted Java applet to execute arbitrary code outside the Java sandbox. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues were addressed by updating to Java version 1.6.0_65. Further information is available via the Java website at

http://www.oracle.com/technetwork/java/javase/releasenotes-136954.html

CVE-ID

CVE-2013-3829

CVE-2013-4002

CVE-2013-5772

CVE-2013-5774

CVE-2013-5776

CVE-2013-5778

CVE-2013-5780

CVE-2013-5782

CVE-2013-5783

CVE-2013-5784

CVE-2013-5787

CVE-2013-5789

CVE-2013-5790

CVE-2013-5797

CVE-2013-5801

CVE-2013-5802

CVE-2013-5803

CVE-2013-5804

CVE-2013-5809

CVE-2013-5812

CVE-2013-5814

CVE-2013-5817

CVE-2013-5818

CVE-2013-5819

CVE-2013-5820

CVE-2013-5823

CVE-2013-5824

CVE-2013-5825

CVE-2013-5829

CVE-2013-5830

CVE-2013-5831

CVE-2013-5832

CVE-2013-5840

CVE-2013-5842

CVE-2013-5843

CVE-2013-5848

CVE-2013-5849

CVE-2013-5850

Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsement. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Contact the vendor for additional information.

Published Date: