CVE-2013-1480: Critical severity ORACLE JRE vulnerability
A flaw was found in the image parser of the Java AWT component. Insufficient validation of raster parameters could lead to Java Virtual Machine memory corruption, possibly allowing untrusted Java application or applet to execute arbitrary code with the virtual machine privileges.
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.240 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" in awtparseImage.c, which triggers memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1480?
CVE-2013-1480 has a high severity rating due to the potential for remote code execution resulting from memory corruption.
How do I fix CVE-2013-1480?
To fix CVE-2013-1480, update to the recommended versions of IcedTea as specified in the vendor's security advisory.
What systems are vulnerable to CVE-2013-1480?
CVE-2013-1480 affects multiple versions of Oracle JDK and JRE as well as IcedTea packages.
What are the exploitation details for CVE-2013-1480?
Exploitation of CVE-2013-1480 could enable an untrusted Java application or applet to execute arbitrary code in the context of the Java Virtual Machine.
Is there a public exploit for CVE-2013-1480?
As of now, there are no widely known public exploits for CVE-2013-1480, but the vulnerability is still deemed serious.