CVE Database
/

CVE-2013-2420

Back to search

CVE-2013-2420

Published: Apr 17, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to insufficient "validation of images" in share/native/sun/awt/image/awt_ImageRep.c, possibly involving offsets.

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SU-2013:0835
vendor-advisory
x_refsource_SUSE
GLSA-201406-32
vendor-advisory
x_refsource_GENTOO
SUSE-SU-2013:0871
vendor-advisory
x_refsource_SUSE
RHSA-2013:0758
vendor-advisory
x_refsource_REDHAT
59167
vdb-entry
x_refsource_BID
APPLE-SA-2013-04-16-2
vendor-advisory
x_refsource_APPLE
MDVSA-2013:145
vendor-advisory
x_refsource_MANDRIVA
TA13-107A
third-party-advisory
x_refsource_CERT
SSRT101252
vendor-advisory
x_refsource_HP
RHSA-2013:1455
vendor-advisory
x_refsource_REDHAT
SSRT101305
vendor-advisory
x_refsource_HP
RHSA-2013:0757
vendor-advisory
x_refsource_REDHAT
HPSBUX02922
vendor-advisory
x_refsource_HP
openSUSE-SU-2013:0777
vendor-advisory
x_refsource_SUSE
oval:org.mitre.oval:def:19354
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:19704
vdb-entry
signature
x_refsource_OVAL
MDVSA-2013:161
vendor-advisory
x_refsource_MANDRIVA
openSUSE-SU-2013:0964
vendor-advisory
x_refsource_SUSE
RHSA-2013:0752
vendor-advisory
x_refsource_REDHAT
USN-1806-1
vendor-advisory
x_refsource_UBUNTU
oval:org.mitre.oval:def:16597
vdb-entry
signature
x_refsource_OVAL
RHSA-2013:1456
vendor-advisory
x_refsource_REDHAT
SUSE-SU-2013:0814
vendor-advisory
x_refsource_SUSE
SUSE-SU-2013:0934
vendor-advisory
x_refsource_SUSE
HPSBUX02889
vendor-advisory
x_refsource_HP

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now