CWE
74
Advisory Published
CVE Published
Updated

CVE-2013-4578

First published: Mon Nov 18 2013(Updated: )

It has been identified that it is possible to inject malicious unsigned bytecode into a signed JAR without failing jarsigner verification. This flaw could be exploited in environments where contents of a verified JAR is considered trusted and unpacked for use. Note that if the signed JAR is used at runtime, with signature intact, a fatal runtime exception is thrown.

Credit: secalert@redhat.com

Affected SoftwareAffected VersionHow to fix
Oracle JDK=1.7.0-update1
Oracle JDK=1.7.0-update10
Oracle JDK=1.7.0-update10_b31
Oracle JDK=1.7.0-update11
Oracle JDK=1.7.0-update11_b32
Oracle JDK=1.7.0-update13
Oracle JDK=1.7.0-update15
Oracle JDK=1.7.0-update17
Oracle JDK=1.7.0-update17_b31
Oracle JDK=1.7.0-update17_b32
Oracle JDK=1.7.0-update2
Oracle JDK=1.7.0-update21
Oracle JDK=1.7.0-update21_b31
Oracle JDK=1.7.0-update25
Oracle JDK=1.7.0-update25_b33
Oracle JDK=1.7.0-update25_b34
Oracle JDK=1.7.0-update25_b35
Oracle JDK=1.7.0-update3
Oracle JDK=1.7.0-update4
Oracle JDK=1.7.0-update40
Oracle JDK=1.7.0-update45
Oracle JDK=1.7.0-update45_b31
Oracle JDK=1.7.0-update45_b32
Oracle JDK=1.7.0-update45_b33
Oracle JDK=1.7.0-update45_b34
Oracle JDK=1.7.0-update5
Oracle JDK=1.7.0-update51
Oracle JDK=1.7.0-update6
Oracle JDK=1.7.0-update7
Oracle JDK=1.7.0-update7_b32
Oracle JDK=1.7.0-update9
Oracle JDK=1.7.0-update9_b31
Oracle JDK=1.7.0-update9_b32
Oracle JRE=1.7.0-update1
Oracle JRE=1.7.0-update10
Oracle JRE=1.7.0-update10_b31
Oracle JRE=1.7.0-update11
Oracle JRE=1.7.0-update11_b32
Oracle JRE=1.7.0-update13
Oracle JRE=1.7.0-update15
Oracle JRE=1.7.0-update17
Oracle JRE=1.7.0-update17_b31
Oracle JRE=1.7.0-update17_b32
Oracle JRE=1.7.0-update2
Oracle JRE=1.7.0-update21
Oracle JRE=1.7.0-update21_b31
Oracle JRE=1.7.0-update25
Oracle JRE=1.7.0-update25_b33
Oracle JRE=1.7.0-update25_b34
Oracle JRE=1.7.0-update25_b35
Oracle JRE=1.7.0-update3
Oracle JRE=1.7.0-update4
Oracle JRE=1.7.0-update40
Oracle JRE=1.7.0-update45
Oracle JRE=1.7.0-update45_b31
Oracle JRE=1.7.0-update45_b32
Oracle JRE=1.7.0-update45_b33
Oracle JRE=1.7.0-update45_b34
Oracle JRE=1.7.0-update5
Oracle JRE=1.7.0-update51
Oracle JRE=1.7.0-update6
Oracle JRE=1.7.0-update7
Oracle JRE=1.7.0-update7_b32
Oracle JRE=1.7.0-update9
Oracle JRE=1.7.0-update9_b31
Oracle JRE=1.7.0-update9_b32
Oracle JDK<=1.7.0
Oracle JRE<=1.7.0

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203