CVE-2013-2450: Medium severity ORACLE JRE vulnerability
It was discovered that the ObjectStreamClass class did not properly protect against circular references. An untrusted Java application or applet could possibly use this flaw to cause a denial of service.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect availability via unknown vectors related to Serialization. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to improper handling of circular references in ObjectStreamClass.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2450?
CVE-2013-2450 is rated as a moderate severity vulnerability, primarily due to the potential for denial of service.
How do I fix CVE-2013-2450?
To fix CVE-2013-2450, you should upgrade to a version of Oracle Java that has addressed this vulnerability, preferably the latest update.
Which versions are affected by CVE-2013-2450?
CVE-2013-2450 affects Oracle Java SE 7 up to update 21, as well as earlier versions of Java.
What types of attacks can exploit CVE-2013-2450?
CVE-2013-2450 can be exploited by untrusted Java applications that create circular references, leading to denial of service.
Is there a workaround for CVE-2013-2450?
The best workaround for CVE-2013-2450 is to avoid running untrusted Java applications or disable Java if possible until the issue is resolved.