First published: Wed Jun 06 2012(Updated: )
Multiple flaws were discovered in the native code implementing fontmanager layout lookup operations. A specially-crafted font file could cause Java Virtual Machine to crash or corrupt its memory, possibly allowing code execution with the virtual machine privileges.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/java | <1.6.0-openjdk-1:1.6.0.0-1.27.1.10.8.el5_8 | 1.6.0-openjdk-1:1.6.0.0-1.27.1.10.8.el5_8 |
redhat/java | <1.6.0-openjdk-1:1.6.0.0-1.48.1.11.3.el6_2 | 1.6.0-openjdk-1:1.6.0.0-1.48.1.11.3.el6_2 |
redhat/java | <1.7.0-openjdk-1:1.7.0.5-2.2.1.el6_3 | 1.7.0-openjdk-1:1.7.0.5-2.2.1.el6_3 |
redhat/java | <1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el6_4 | 1.6.0-ibm-1:1.6.0.14.0-1jpp.1.el6_4 |
redhat/java | <1.4.2-ibm-sap-0:1.4.2.13.13.sap-1jpp.2.el5 | 1.4.2-ibm-sap-0:1.4.2.13.13.sap-1jpp.2.el5 |
redhat/java | <1.6.0-sun-1:1.6.0.33-1jpp.1.el5_8 | 1.6.0-sun-1:1.6.0.33-1jpp.1.el5_8 |
redhat/java | <1.6.0-ibm-1:1.6.0.11.0-1jpp.1.el5_8 | 1.6.0-ibm-1:1.6.0.11.0-1jpp.1.el5_8 |
redhat/java | <1.4.2-ibm-0:1.4.2.13.13-1jpp.1.el5_8 | 1.4.2-ibm-0:1.4.2.13.13-1jpp.1.el5_8 |
redhat/java | <1.5.0-ibm-1:1.5.0.14.0-1jpp.1.el5_8 | 1.5.0-ibm-1:1.5.0.14.0-1jpp.1.el5_8 |
redhat/java | <1.6.0-sun-1:1.6.0.33-1jpp.1.el6_2 | 1.6.0-sun-1:1.6.0.33-1jpp.1.el6_2 |
redhat/java | <1.7.0-oracle-1:1.7.0.5-1jpp.1.el6 | 1.7.0-oracle-1:1.7.0.5-1jpp.1.el6 |
redhat/java | <1.6.0-ibm-1:1.6.0.11.0-1jpp.1.el6_3 | 1.6.0-ibm-1:1.6.0.11.0-1jpp.1.el6_3 |
redhat/java | <1.5.0-ibm-1:1.5.0.14.0-1jpp.1.el6_3 | 1.5.0-ibm-1:1.5.0.14.0-1jpp.1.el6_3 |
redhat/java | <1.7.0-ibm-1:1.7.0.2.0-1jpp.3.el6_3 | 1.7.0-ibm-1:1.7.0.2.0-1jpp.3.el6_3 |
Oracle JDK 6 | <=1.7.0 | |
Oracle JRE | <=1.7.0 | |
Oracle JDK 6 | <=1.6.0 | |
Oracle JRE | <=1.6.0 | |
Sun JDK | <=1.5.0 | |
Sun JRE | <=1.5.0 | |
Sun JDK | <=1.4.2_37 | |
Sun JRE | <=1.4.2_37 | |
Oracle Javafx | <=2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2012-1713 is classified as a critical vulnerability with a severity score of 10.
To mitigate CVE-2012-1713, update to the latest versions of the affected Java Runtime Environment as specified in the remediation details.
CVE-2012-1713 affects Oracle Java SE versions 7 update 4 and earlier, 6 update 32 and earlier, and several other older Java and JavaFX releases.
Yes, CVE-2012-1713 allows remote attackers to exploit the vulnerability affecting confidentiality, integrity, and availability.
The potential impacts of CVE-2012-1713 include unauthorized access, data breaches, and disruption of services.