CVE-2013-2463: Critical severity ORACLE JRE vulnerability
It was discovered that the 2D component did not properly verify certain image attributes. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image attribute verification" in 2D.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2463?
CVE-2013-2463 is classified as a medium severity vulnerability.
How can I fix CVE-2013-2463?
To fix CVE-2013-2463, update your Java Runtime Environment to the latest version provided by Oracle.
What type of vulnerability is CVE-2013-2463?
CVE-2013-2463 is a security vulnerability that potentially allows an untrusted Java application to bypass sandbox restrictions.
Which Java versions are affected by CVE-2013-2463?
CVE-2013-2463 affects Oracle Java SE 7 Update 2 and earlier versions.
Is CVE-2013-2463 applicable to both JDK and JRE?
Yes, CVE-2013-2463 is applicable to both Oracle JDK and JRE versions affected.