CVE-2013-2464: Critical severity ORACLE JRE vulnerability
Oracle Java SE 7 Update 25 fixes an unspecified vulnerability in the 2D component (CVE-2013-2464). Upstream has CVSSv2 scored this issue as: 10.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2463, CVE-2013-2465, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471, CVE-2013-2472, and CVE-2013-2473.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2013-2464?
CVE-2013-2464 is rated with a CVSSv2 score of 10.0, indicating a critical vulnerability.
How do I fix CVE-2013-2464?
To address CVE-2013-2464, update your Oracle Java SE to version 7 Update 25 or later.
What software is affected by CVE-2013-2464?
CVE-2013-2464 affects multiple versions of Oracle Java SE, especially versions prior to Update 25.
Can CVE-2013-2464 be exploited remotely?
Yes, CVE-2013-2464 can be exploited remotely, allowing attackers to execute arbitrary code.
Is there a workaround for CVE-2013-2464?
Disabling Java in your web browser can act as a temporary workaround for CVE-2013-2464 until systems can be updated.