CVE-2013-2473: Critical severity ORACLE JRE vulnerability
It was discovered that the ByteBandedRaster class of the 2D component did not properly verify that the data buffer size fits the raster attributes. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
Other sources
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ByteBandedRaster size checks" in 2D.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2473?
CVE-2013-2473 is considered a high severity vulnerability due to its ability to bypass Java sandbox restrictions.
How does CVE-2013-2473 affect Java applications?
CVE-2013-2473 allows untrusted Java applications or applets to exploit the flaw and potentially execute unsafe operations.
How do I fix CVE-2013-2473?
To fix CVE-2013-2473, update the Java Runtime Environment (JRE) or Java Development Kit (JDK) to the latest version released by Oracle.
Which versions are affected by CVE-2013-2473?
CVE-2013-2473 affects multiple versions of Oracle JRE and JDK, specifically 1.5.0 through 1.7.0.
Is there a workaround for CVE-2013-2473?
There are no effective workarounds for CVE-2013-2473, so updating to the latest version is the recommended course of action.