CVE-2013-0445: Critical severity oracle jre vulnerability
It was discovered that AWT component in the OpenJDK did not properly check privileges of the code. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions.
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, and 5.0 through Update 38, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to an improper check of "privileges of the code" that bypasses the sandbox.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0445?
The CVE-2013-0445 vulnerability is considered high severity as it allows untrusted Java applications to bypass Java sandbox restrictions.
How do I fix CVE-2013-0445?
To fix CVE-2013-0445, update to the latest versions of affected packages like IcedTea6 or IcedTea7, specifically versions 1.11.6, 1.12.1, 2.1.5, 2.2.5, or 2.3.6.
Which systems are affected by CVE-2013-0445?
CVE-2013-0445 affects multiple versions of Oracle JDK and JRE, as well as the IcedTea packages on certain Linux distributions.
Is CVE-2013-0445 still a concern in 2023?
While CVE-2013-0445 is several years old, systems still using the vulnerable software versions remain at risk and should be updated promptly.
What types of exploits can be performed due to CVE-2013-0445?
Exploiting CVE-2013-0445 can lead to unauthorized access and execution of arbitrary code within the Java application environment.