CVE Database
/

CVE-2013-0401

Back to search

CVE-2013-0401

Published: Mar 8, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to execute arbitrary code via vectors related to AWT, as demonstrated by Ben Murphy during a Pwn2Own competition at CanSecWest 2013. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to invocation of the system class loader by the sun.awt.datatransfer.ClassLoaderObjectInputStream class, which allows remote attackers to bypass Java sandbox restrictions.

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SU-2013:0835
vendor-advisory
x_refsource_SUSE
GLSA-201406-32
vendor-advisory
x_refsource_GENTOO
SUSE-SU-2013:0871
vendor-advisory
x_refsource_SUSE
RHSA-2013:0758
vendor-advisory
x_refsource_REDHAT
MDVSA-2013:145
vendor-advisory
x_refsource_MANDRIVA
TA13-107A
third-party-advisory
x_refsource_CERT
SSRT101252
vendor-advisory
x_refsource_HP
RHSA-2013:1455
vendor-advisory
x_refsource_REDHAT
SSRT101305
vendor-advisory
x_refsource_HP
RHSA-2013:0757
vendor-advisory
x_refsource_REDHAT
HPSBUX02922
vendor-advisory
x_refsource_HP
openSUSE-SU-2013:0777
vendor-advisory
x_refsource_SUSE
MDVSA-2013:161
vendor-advisory
x_refsource_MANDRIVA
openSUSE-SU-2013:0964
vendor-advisory
x_refsource_SUSE
RHSA-2013:0752
vendor-advisory
x_refsource_REDHAT
USN-1806-1
vendor-advisory
x_refsource_UBUNTU
oval:org.mitre.oval:def:16297
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:19641
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:19463
vdb-entry
signature
x_refsource_OVAL
RHSA-2013:1456
vendor-advisory
x_refsource_REDHAT
SUSE-SU-2013:0814
vendor-advisory
x_refsource_SUSE
HPSBUX02889
vendor-advisory
x_refsource_HP

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now