CVE-2013-2429: High severity ORACLE JRE vulnerability
It was discovered that JPEGImageWriter did not protect against modification of its state while performing certain native code operations. An untrusted Java application or applet could possibly use this flaw to trigger JVM memory corruption.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "JPEGImageWriter state corruption" when using native code, which triggers memory corruption.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2429?
CVE-2013-2429 is considered to be of high severity due to potential memory corruption leading to exploitation.
How do I fix CVE-2013-2429?
To fix CVE-2013-2429, update your Java Runtime Environment or JDK to a version that is patched against this vulnerability.
Which software versions are affected by CVE-2013-2429?
CVE-2013-2429 affects multiple versions of Oracle JRE and JDK, particularly those prior to 1.7.0_update41 and 1.6.0_update43.
Can CVE-2013-2429 be exploited by untrusted applications?
Yes, CVE-2013-2429 can be exploited by untrusted Java applications or applets, leading to potential memory corruption.
Is there a workaround for CVE-2013-2429 if I cannot update?
There are no specific workarounds documented for CVE-2013-2429, so updating to a secure version is recommended.