CVE-2013-2430: High severity ORACLE JRE vulnerability
It was discovered that JPEGImageReader did not protect against modification of its state while performing certain native code operations. An untrusted Java application or applet could possibly use this flaw to trigger JVM memory corruption.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; JavaFX 2.2.7 and earlier; and OpenJDK 6 and 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ImageIO. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "JPEGImageReader state corruption" when using native code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2430?
CVE-2013-2430 has a CVSS score of 7.5, indicating a high severity vulnerability.
How do I fix CVE-2013-2430?
To fix CVE-2013-2430, update your Java Runtime Environment (JRE) to the latest version available from Oracle or the specific patch provided by your software vendor.
What products are affected by CVE-2013-2430?
CVE-2013-2430 affects multiple versions of the Oracle JRE and JDK, including versions 1.6.0 through 1.7.0, and specific versions of IcedTea.
Can CVE-2013-2430 be exploited remotely?
Yes, CVE-2013-2430 can be exploited remotely by untrusted Java applications or applets.
What mitigations are recommended for CVE-2013-2430?
It is recommended to disable Java in browsers or restrict permissions for Java applications until the patch is applied.