AWS Security Advisories · October 2013 — AWS Security Advisories
9 advisories 40 CVEs 1 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2013-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2013-235

ALAS · AL1PoC exploitCritical2013-10-23

ALAS-2013-235: java-1.7.0-openjdk (critical)

CVEs:CVE-2013-3829CVE-2013-4002CVE-2013-5772CVE-2013-5774CVE-2013-5778CVE-2013-5780CVE-2013-5782CVE-2013-5783CVE-2013-5784CVE-2013-5790CVE-2013-5797CVE-2013-5800CVE-2013-5802CVE-2013-5803CVE-2013-5804CVE-2013-5809CVE-2013-5814CVE-2013-5817CVE-2013-5820CVE-2013-5823CVE-2013-5825CVE-2013-5829CVE-2013-5830CVE-2013-5838CVE-2013-5840CVE-2013-5842CVE-2013-5849CVE-2013-5850CVE-2013-5851

Affected products

ProductStatusVendorPackageEcosystem
java-1.7.0-openjdk affected Amazon java-1.7.0-openjdk
Upstream advisory

ALAS-2013-238

ALAS · AL1EPSS <= 49%Important2013-10-23

ALAS-2013-238: mod_fcgid (important)

CVEs:CVE-2013-4365

Affected products

ProductStatusVendorPackageEcosystem
mod_fcgid affected Amazon mod_fcgid
Upstream advisory

ALAS-2013-239

ALAS · AL1EPSS <= 49%Important2013-10-23

ALAS-2013-239: mod24_fcgid (important)

CVEs:CVE-2013-4365

Affected products

ProductStatusVendorPackageEcosystem
mod24_fcgid affected Amazon mod24_fcgid
Upstream advisory

ALAS-2013-234

ALAS · AL1EPSS <= 49%Important2013-10-23

ALAS-2013-234: xorg-x11-server (important)

CVEs:CVE-2013-4396

Affected products

ProductStatusVendorPackageEcosystem
xorg-x11-server affected Amazon xorg-x11-server
Upstream advisory

ALAS-2013-231

ALAS · AL1EPSS <= 49%Medium2013-10-16

ALAS-2013-231: rubygems (medium)

CVEs:CVE-2013-4363

Affected products

ProductStatusVendorPackageEcosystem
rubygems affected Amazon rubygems
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.