CVE-2012-1713: Critical severity Oracle JDK vulnerability
Multiple flaws were discovered in the native code implementing fontmanager layout lookup operations. A specially-crafted font file could cause Java Virtual Machine to crash or corrupt its memory, possibly allowing code execution with the virtual machine privileges.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, 1.4.237 and earlier, and JavaFX 2.1 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2012-1713?
CVE-2012-1713 is classified as a critical vulnerability with a severity score of 10.
How do I fix CVE-2012-1713?
To mitigate CVE-2012-1713, update to the latest versions of the affected Java Runtime Environment as specified in the remediation details.
What software is affected by CVE-2012-1713?
CVE-2012-1713 affects Oracle Java SE versions 7 update 4 and earlier, 6 update 32 and earlier, and several other older Java and JavaFX releases.
Can CVE-2012-1713 be exploited remotely?
Yes, CVE-2012-1713 allows remote attackers to exploit the vulnerability affecting confidentiality, integrity, and availability.
What are the potential impacts of CVE-2012-1713?
The potential impacts of CVE-2012-1713 include unauthorized access, data breaches, and disruption of services.