Back to search
CVE-2013-1493
Published: Mar 4, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
oval:org.mitre.oval:def:19246
vdb-entry
signature
x_refsource_OVAL
openSUSE-SU-2013:0438
vendor-advisory
x_refsource_SUSE
GLSA-201406-32
vendor-advisory
x_refsource_GENTOO
24904
exploit
x_refsource_EXPLOIT-DB
58238
vdb-entry
x_refsource_BID
MDVSA-2013:095
vendor-advisory
x_refsource_MANDRIVA
1029803
vdb-entry
x_refsource_SECTRACK
SSRT101156
vendor-advisory
x_refsource_HP
RHSA-2013:0604
vendor-advisory
x_refsource_REDHAT
TA13-064A
third-party-advisory
x_refsource_CERT
openSUSE-SU-2013:0430
vendor-advisory
x_refsource_SUSE
RHSA-2013:1455
vendor-advisory
x_refsource_REDHAT
https://twitter.com/jduck1337/status/307629902574800897
x_refsource_MISC
[distro-pkg-dev] 20130304 [SECURITY] IcedTea6 1.11.9 and 1.12.4 Released!
mailing-list
x_refsource_MLIST
SUSE-SU-2013:0434
vendor-advisory
x_refsource_SUSE
HPSBUX02857
vendor-advisory
x_refsource_HP
SUSE-SU-2013:0701
vendor-advisory
x_refsource_SUSE
USN-1755-2
vendor-advisory
x_refsource_UBUNTU
SSRT101103
vendor-advisory
x_refsource_HP
VU#688246
third-party-advisory
x_refsource_CERT-VN
https://bugzilla.redhat.com/show_bug.cgi?id=917553
x_refsource_CONFIRM
RHSA-2013:1456
vendor-advisory
x_refsource_REDHAT
HPSBMU02964
vendor-advisory
x_refsource_HP
HPSBUX02864
vendor-advisory
x_refsource_HP
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0088
x_refsource_CONFIRM
oval:org.mitre.oval:def:19477
vdb-entry
signature
x_refsource_OVAL
RHSA-2013:0603
vendor-advisory
x_refsource_REDHAT
RHSA-2013:0601
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now