CVE-2013-2431: Critical severity ORACLE JRE vulnerability
It was discovered that the Hotspot component did not properly handle certain intrinsic frames. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to bypassing the Java sandbox using "method handle intrinsic frames."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2431?
CVE-2013-2431 has been rated with a high severity level due to its potential to allow untrusted Java applications to bypass sandbox restrictions.
How do I fix CVE-2013-2431?
To fix CVE-2013-2431, update your Java Runtime Environment (JRE) or Java Development Kit (JDK) to the latest version available.
Which versions of Oracle JRE are affected by CVE-2013-2431?
CVE-2013-2431 affects several versions of Oracle JRE including version 1.7.0 and its updates up to update 15.
What types of applications could be affected by CVE-2013-2431?
Untrusted Java applications and applets running in the Java sandbox could be affected by CVE-2013-2431.
Is CVE-2013-2431 a known vulnerability in IcedTea packages?
Yes, CVE-2013-2431 is also recognized as a vulnerability affecting specific versions of IcedTea packages, such as IcedTea6 and IcedTea7.