CVE-2013-2436: Critical severity ORACLE JRE vulnerability
It was discovered that the sun.util.invoke.Wrapper did not perform type checks correctly when converting wrapped values. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-1488 and CVE-2013-2426. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "type checks" and "method handle binding" involving Wrapper.convert.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2436?
The severity of CVE-2013-2436 is critical with a CVSS score of 9.3.
How do I fix CVE-2013-2436?
To fix CVE-2013-2436, update to the latest version of Oracle JRE or Oracle JDK as provided by Oracle.
What systems are affected by CVE-2013-2436?
CVE-2013-2436 affects Oracle JRE, Oracle JDK, and certain versions of Red Hat IcedTea.
Can CVE-2013-2436 allow malicious programs to bypass security restrictions?
Yes, CVE-2013-2436 can allow untrusted Java applications to bypass Java sandbox restrictions.
When was CVE-2013-2436 published?
CVE-2013-2436 was published on April 16, 2013.