CWE
74
Advisory Published
CVE Published
Updated

CVE-2013-4578

First published: Mon Nov 18 2013(Updated: )

It has been identified that it is possible to inject malicious unsigned bytecode into a signed JAR without failing jarsigner verification. This flaw could be exploited in environments where contents of a verified JAR is considered trusted and unpacked for use. Note that if the signed JAR is used at runtime, with signature intact, a fatal runtime exception is thrown.

Credit: secalert@redhat.com

Affected SoftwareAffected VersionHow to fix
Oracle Java SE 7=1.7.0-update1
Oracle Java SE 7=1.7.0-update10
Oracle Java SE 7=1.7.0-update10_b31
Oracle Java SE 7=1.7.0-update11
Oracle Java SE 7=1.7.0-update11_b32
Oracle Java SE 7=1.7.0-update13
Oracle Java SE 7=1.7.0-update15
Oracle Java SE 7=1.7.0-update17
Oracle Java SE 7=1.7.0-update17_b31
Oracle Java SE 7=1.7.0-update17_b32
Oracle Java SE 7=1.7.0-update2
Oracle Java SE 7=1.7.0-update21
Oracle Java SE 7=1.7.0-update21_b31
Oracle Java SE 7=1.7.0-update25
Oracle Java SE 7=1.7.0-update25_b33
Oracle Java SE 7=1.7.0-update25_b34
Oracle Java SE 7=1.7.0-update25_b35
Oracle Java SE 7=1.7.0-update3
Oracle Java SE 7=1.7.0-update4
Oracle Java SE 7=1.7.0-update40
Oracle Java SE 7=1.7.0-update45
Oracle Java SE 7=1.7.0-update45_b31
Oracle Java SE 7=1.7.0-update45_b32
Oracle Java SE 7=1.7.0-update45_b33
Oracle Java SE 7=1.7.0-update45_b34
Oracle Java SE 7=1.7.0-update5
Oracle Java SE 7=1.7.0-update51
Oracle Java SE 7=1.7.0-update6
Oracle Java SE 7=1.7.0-update7
Oracle Java SE 7=1.7.0-update7_b32
Oracle Java SE 7=1.7.0-update9
Oracle Java SE 7=1.7.0-update9_b31
Oracle Java SE 7=1.7.0-update9_b32
Oracle JRE=1.7.0-update1
Oracle JRE=1.7.0-update10
Oracle JRE=1.7.0-update10_b31
Oracle JRE=1.7.0-update11
Oracle JRE=1.7.0-update11_b32
Oracle JRE=1.7.0-update13
Oracle JRE=1.7.0-update15
Oracle JRE=1.7.0-update17
Oracle JRE=1.7.0-update17_b31
Oracle JRE=1.7.0-update17_b32
Oracle JRE=1.7.0-update2
Oracle JRE=1.7.0-update21
Oracle JRE=1.7.0-update21_b31
Oracle JRE=1.7.0-update25
Oracle JRE=1.7.0-update25_b33
Oracle JRE=1.7.0-update25_b34
Oracle JRE=1.7.0-update25_b35
Oracle JRE=1.7.0-update3
Oracle JRE=1.7.0-update4
Oracle JRE=1.7.0-update40
Oracle JRE=1.7.0-update45
Oracle JRE=1.7.0-update45_b31
Oracle JRE=1.7.0-update45_b32
Oracle JRE=1.7.0-update45_b33
Oracle JRE=1.7.0-update45_b34
Oracle JRE=1.7.0-update5
Oracle JRE=1.7.0-update51
Oracle JRE=1.7.0-update6
Oracle JRE=1.7.0-update7
Oracle JRE=1.7.0-update7_b32
Oracle JRE=1.7.0-update9
Oracle JRE=1.7.0-update9_b31
Oracle JRE=1.7.0-update9_b32
Oracle Java SE 7<=1.7.0
Oracle JRE<=1.7.0

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2013-4578?

    CVE-2013-4578 is classified as a critical vulnerability due to the potential for arbitrary code execution through malicious bytecode injection.

  • How do I fix CVE-2013-4578?

    To mitigate CVE-2013-4578, update to the latest version of Oracle JDK or JRE, as the vulnerability has been addressed in subsequent updates.

  • What versions of software are affected by CVE-2013-4578?

    CVE-2013-4578 affects various versions of Oracle JDK and JRE 1.7.0 up to update 51.

  • Can CVE-2013-4578 be exploited remotely?

    Yes, CVE-2013-4578 can be exploited remotely if the vulnerable software is deployed in an environment that treats untrusted content as trusted.

  • What are the potential impacts of CVE-2013-4578?

    The exploitation of CVE-2013-4578 can lead to unauthorized access and control over affected systems, resulting in data breaches or service disruptions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203