CVE-2013-1478: Integer Overflow
A flaw was found in the image parser of the Java 2D component. Insufficient validation of raster parameters could lead to Java Virtual Machine memory corruption, possibly allowing untrusted Java application or applet to execute arbitrary code with the virtual machine privileges.
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.240 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" that can trigger an integer overflow and memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1478?
CVE-2013-1478 has been classified as a critical severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2013-1478?
To fix CVE-2013-1478, update to the latest versions of the affected software, specifically Java binaries like Oracle JRE 1.7.0 or IcedTea versions listed in the vulnerability report.
What versions are affected by CVE-2013-1478?
CVE-2013-1478 affects multiple versions of Oracle JRE, JDK, and IcedTea, particularly those prior to 1.6.0-update34 and 2.3.6.
What kind of impact can CVE-2013-1478 have on systems?
The impact of CVE-2013-1478 may include system compromise through memory corruption, leading to untrusted applications executing arbitrary code with elevated privileges.
Is there a workaround for CVE-2013-1478 if I cannot update immediately?
Currently, there are no recommended workarounds for CVE-2013-1478; updating to a secure version is necessary for protection.