AWS Security Advisories · April 2013 — AWS Security Advisories
12 advisories 52 CVEs 1 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2013-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2013-183

ALAS · AL1ExploitedCISA KEV listedCritical2013-04-18

ALAS-2013-183: java-1.7.0-openjdk (critical)

CVEs:CVE-2013-0401CVE-2013-1488CVE-2013-1518CVE-2013-1537CVE-2013-1557CVE-2013-1558CVE-2013-1569CVE-2013-2383CVE-2013-2384CVE-2013-2415CVE-2013-2417CVE-2013-2419CVE-2013-2420CVE-2013-2421CVE-2013-2422CVE-2013-2423CVE-2013-2424CVE-2013-2426CVE-2013-2429CVE-2013-2430CVE-2013-2431CVE-2013-2436

Affected products

ProductStatusVendorPackageEcosystem
java-1.7.0-openjdk affected Amazon java-1.7.0-openjdk
Upstream advisory

ALAS-2013-185

ALAS · AL1Weaponized exploitImportant2013-04-25

ALAS-2013-185: java-1.6.0-openjdk (important)

CVEs:CVE-2013-0401CVE-2013-1488CVE-2013-1518CVE-2013-1537CVE-2013-1557CVE-2013-1558CVE-2013-1569CVE-2013-2383CVE-2013-2384CVE-2013-2415CVE-2013-2417CVE-2013-2419CVE-2013-2420CVE-2013-2421CVE-2013-2422CVE-2013-2424CVE-2013-2426CVE-2013-2429CVE-2013-2430CVE-2013-2431

Affected products

ProductStatusVendorPackageEcosystem
java-1.6.0-openjdk affected Amazon java-1.6.0-openjdk
Upstream advisory

ALAS-2013-179

ALAS · AL1Weaponized exploitMedium2013-04-11

ALAS-2013-179: lighttpd (medium)

CVEs:CVE-2012-5533

Affected products

ProductStatusVendorPackageEcosystem
lighttpd affected Amazon lighttpd
Upstream advisory

ALAS-2013-184

ALAS · AL1EPSS <= 49%Low2013-04-18

ALAS-2013-184: 389-ds-base (low)

CVEs:CVE-2013-1897

Affected products

ProductStatusVendorPackageEcosystem
389-ds-base affected Amazon 389-ds-base
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.