CVE-2013-2444: Medium severity ORACLE JRE vulnerability
It was discovered that the AWT component did not properly manage and restrict certain resources related to the processing of fonts. An untrusted Java application or applet could possibly use this flaw to exhaust available resources and cause a denial of service.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier; JavaFX 2.2.21 and earlier; and OpenJDK 7 allows remote attackers to affect availability via vectors related to AWT. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue does not "properly manage and restrict certain resources related to the processing of fonts," possibly involving temporary files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2444?
CVE-2013-2444 has a severity rating of medium, as it enables denial of service attacks.
How do I fix CVE-2013-2444?
To fix CVE-2013-2444, update to a later version of the Oracle Java Runtime Environment or JDK that addresses this vulnerability.
What are the affected versions in CVE-2013-2444?
CVE-2013-2444 affects Oracle Java Runtime Environment versions up to and including 1.7.0-update21.
What types of attacks can exploit CVE-2013-2444?
CVE-2013-2444 can be exploited through untrusted Java applications or applets leading to resource exhaustion and denial of service.
Is CVE-2013-2444 applicable to Oracle JDK?
Yes, CVE-2013-2444 affects multiple versions of Oracle JDK, specifically versions prior to the security updates addressing this issue.