First published: Sat Feb 02 2013(Updated: )
Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from a third party that the issue allows remote attackers to execute arbitrary code via vectors related to an "invalid type cast" and exposed native methods in the T2KGlyph class.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle JavaFX | <=2.2.4 | |
Oracle JavaFX | =2.0 | |
Oracle JavaFX | =2.0.2 | |
Oracle JavaFX | =2.0.3 | |
Oracle JavaFX | =2.1 | |
Oracle JavaFX | =2.2 | |
Oracle JavaFX | =2.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4305 has been classified as a vulnerability that could impact confidentiality, integrity, and availability.
To mitigate CVE-2012-4305, users should upgrade to a later, patched version of Oracle JavaFX beyond 2.2.4.
CVE-2012-4305 affects Oracle JavaFX versions 2.0 through 2.2.4.
Yes, CVE-2012-4305 can be exploited by remote attackers through unknown vectors.
There are no known workarounds for CVE-2012-4305, updating to a fixed version is recommended.