CVE-2013-1488: Code Injection
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-1488 to the following vulnerability:
Oracle Java 7 Update 17, and possibly other versions, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, as demonstrated by James Forshaw during a Pwn2Own competition at CanSecWest 2013.
References: [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1488 [2] http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157 [3] http://www.zdnet.com/pwn2own-down-go-all-the-browsers-7000012283/ [4] https://twitter.com/thezdi/status/309425888188043264
Other sources
The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString calls," and the JDBC driver manager, as demonstrated by James Forshaw during a Pwn2Own competition at CanSecWest 2013.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1488?
CVE-2013-1488 has a high severity level as it allows remote attackers to execute arbitrary code.
How do I fix CVE-2013-1488?
To fix CVE-2013-1488, update Oracle Java to version 1.7.0-update18 or later, or use a patched version of IcedTea.
Which versions are affected by CVE-2013-1488?
CVE-2013-1488 affects Oracle Java 7 Update 17 and older versions, as well as specific older versions of IcedTea.
Who can be impacted by CVE-2013-1488?
Remote attackers can exploit CVE-2013-1488 to impact users running vulnerable versions of Oracle Java or IcedTea.
What type of attack is possible with CVE-2013-1488?
CVE-2013-1488 allows attackers to execute arbitrary code on the affected system, leading to potential full control.