CVE-2013-1500: Low severity ORACLE JRE vulnerability
It was discovered that the 2D component created shared memory segments with insecure permissions. A local attacker could use this flaw to read or write to the shared memory segment.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality and integrity via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to weak permissions for shared memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1500?
The severity of CVE-2013-1500 is high due to the potential for local attackers to exploit insecure permissions on shared memory segments.
How do I fix CVE-2013-1500?
To fix CVE-2013-1500, you should upgrade to a patched version of Oracle Java SE beyond Update 21.
What versions of software are affected by CVE-2013-1500?
CVE-2013-1500 affects Oracle Java SE 7 Update 21 and earlier versions.
Can CVE-2013-1500 be exploited remotely?
No, CVE-2013-1500 requires local access to the system to exploit the vulnerability.
What type of vulnerability is CVE-2013-1500?
CVE-2013-1500 is a local privilege escalation vulnerability affecting the Java Runtime Environment.