CVE-2013-2471: Critical severity ORACLE JRE vulnerability
It was discovered that the IntegerComponentRaster class did not properly verify that the data buffer size fits the raster attributes. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect IntegerComponentRaster size checks."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2471?
CVE-2013-2471 has been classified as a high severity vulnerability due to its potential to bypass Java sandbox restrictions.
How do I fix CVE-2013-2471?
To fix CVE-2013-2471, upgrade to a version of the Java Runtime Environment or Java Development Kit that is not affected by this vulnerability, typically versions beyond the updates listed in the CVE.
Which Java versions are affected by CVE-2013-2471?
CVE-2013-2471 affects Oracle Java Runtime Environment and Oracle JDK versions 1.7.0 through update 21 and various versions of 1.6.0 and 1.5.0.
Is CVE-2013-2471 exploitable via a network attack?
Yes, CVE-2013-2471 can be exploited by an untrusted Java application or applet over a network, potentially allowing for unauthorized access to system resources.
What impact could CVE-2013-2471 have on my system?
Exploitation of CVE-2013-2471 could lead to compromised confidentiality, integrity, and availability of the affected systems by allowing malicious code to run outside the confines of the Java sandbox.