CVE-2013-3829: Medium severity oracle jre vulnerability
It was discovered that java.util.TimeZone does not properly restrict changing the time zone to the default time zone. An untrusted Java application or applet could exploit this to change the default time zone of their application contexts.
Other sources
Unspecified vulnerability in the Java SE, Java SE Embedded component in Oracle Java SE Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3829?
CVE-2013-3829 has been rated as a high severity vulnerability due to its ability to allow untrusted Java applications to alter default time zones.
How do I fix CVE-2013-3829?
To fix CVE-2013-3829, users should update affected versions of Java to the latest secure release provided by Oracle or their vendor.
What software is affected by CVE-2013-3829?
CVE-2013-3829 affects various versions of Oracle JRE and JDK as well as different versions of the IcedTea package.
Can CVE-2013-3829 be exploited remotely?
Yes, CVE-2013-3829 can potentially be exploited remotely by running untrusted Java applications or applets.
What are the potential impacts of CVE-2013-3829?
Exploitation of CVE-2013-3829 may allow attackers to change application contexts' default time zones, potentially disrupting time-sensitive processes.