CVE-2013-2445: High severity ORACLE JRE vulnerability
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect availability via unknown vectors related to Hotspot. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "handling of memory allocation errors."
Other sources
Various memory allocating parts of the Hotspot component did not correctly handle out-of-memory errors. An untrusted Java application or applet could possibly use these flaws to terminate the Java VM.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2445?
CVE-2013-2445 has a medium severity rating, primarily affecting the availability of the vulnerable Java Runtime Environment.
How do I fix CVE-2013-2445?
To mitigate CVE-2013-2445, users should update their Java installations to version 7 Update 22 or later.
Which versions of Java are affected by CVE-2013-2445?
CVE-2013-2445 affects Oracle Java SE 7 Update 21 and earlier, as well as Java SE 6 Update 45 and earlier, and Java SE 5.0 Update 45 or earlier.
What kind of attacks can CVE-2013-2445 enable?
CVE-2013-2445 may allow remote attackers to affect the availability of the Java Runtime Environment through unspecified vectors.
Who is responsible for addressing CVE-2013-2445?
The responsibility for addressing CVE-2013-2445 lies with both Oracle and users who need to ensure their Java installations are up-to-date.