CVE-2013-2447: Medium severity ORACLE JRE vulnerability
It was discovered that the Networking component did not properly prevent the local address from being revealed. An untrusted Java application or applet could possibly use this flaw to disclose the local address.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Networking. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to obtain a socket's local address via vectors involving inconsistencies between Socket.getLocalAddress and InetAddress.getLocalHost.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2447?
The severity of CVE-2013-2447 is classified as moderate, as it can lead to disclosure of local addresses in untrusted Java applications.
How do I fix CVE-2013-2447?
To fix CVE-2013-2447, update to the latest version of the Oracle Java Runtime Environment or Java Development Kit that addresses this vulnerability.
What software is affected by CVE-2013-2447?
CVE-2013-2447 affects various versions of Oracle Java Runtime Environment (JRE) and Oracle JDK, particularly those before update 45.
Are there any workarounds for CVE-2013-2447?
A temporary workaround for CVE-2013-2447 includes disabling the use of the Java plugin in web browsers to prevent untrusted applications from running.
Is CVE-2013-2447 being actively exploited?
There have been reports indicating potential exploitation of CVE-2013-2447 in the wild, making it crucial to apply the necessary updates.