CVE-2013-4578: Medium severity oracle java se 7 vulnerability

Published Nov 18, 2013
·
Updated

It has been identified that it is possible to inject malicious unsigned bytecode into a signed JAR without failing jarsigner verification. This flaw could be exploited in environments where contents of a verified JAR is considered trusted and unpacked for use.

Note that if the signed JAR is used at runtime, with signature intact, a fatal runtime exception is thrown.

Other sources

jarsigner in OpenJDK and Oracle Java SE before 7u51 allows remote attackers to bypass a code-signing protection mechanism and inject unsigned bytecode into a signed JAR file by leveraging improper file validation.

MITRE

Affected Software

68 affected components
Oracle JDK=1.7.0-update1
Oracle JDK=1.7.0-update10
Oracle JDK=1.7.0-update10_b31
Oracle JDK=1.7.0-update11
Oracle JDK=1.7.0-update11_b32
Oracle JDK=1.7.0-update13
Oracle JDK=1.7.0-update15
Oracle JDK=1.7.0-update17
Oracle JDK=1.7.0-update17_b31
Oracle JDK=1.7.0-update17_b32
Oracle JDK=1.7.0-update2
Oracle JDK=1.7.0-update21
Oracle JDK=1.7.0-update21_b31
Oracle JDK=1.7.0-update25
Oracle JDK=1.7.0-update25_b33
Oracle JDK=1.7.0-update25_b34
Oracle JDK=1.7.0-update25_b35
Oracle JDK=1.7.0-update3
Oracle JDK=1.7.0-update4
Oracle JDK=1.7.0-update40
Oracle JDK=1.7.0-update45
Oracle JDK=1.7.0-update45_b31
Oracle JDK=1.7.0-update45_b32
Oracle JDK=1.7.0-update45_b33
Oracle JDK=1.7.0-update45_b34
Oracle JDK=1.7.0-update5
Oracle JDK=1.7.0-update51
Oracle JDK=1.7.0-update6
Oracle JDK=1.7.0-update7
Oracle JDK=1.7.0-update7_b32
Oracle JDK=1.7.0-update9
Oracle JDK=1.7.0-update9_b31
Oracle JDK=1.7.0-update9_b32
ORACLE JRE=1.7.0-update1
ORACLE JRE=1.7.0-update10
ORACLE JRE=1.7.0-update10_b31
ORACLE JRE=1.7.0-update11
ORACLE JRE=1.7.0-update11_b32
ORACLE JRE=1.7.0-update13
ORACLE JRE=1.7.0-update15
ORACLE JRE=1.7.0-update17
ORACLE JRE=1.7.0-update17_b31
ORACLE JRE=1.7.0-update17_b32
ORACLE JRE=1.7.0-update2
ORACLE JRE=1.7.0-update21
ORACLE JRE=1.7.0-update21_b31
ORACLE JRE=1.7.0-update25
ORACLE JRE=1.7.0-update25_b33
ORACLE JRE=1.7.0-update25_b34
ORACLE JRE=1.7.0-update25_b35
ORACLE JRE=1.7.0-update3
ORACLE JRE=1.7.0-update4
ORACLE JRE=1.7.0-update40
ORACLE JRE=1.7.0-update45
ORACLE JRE=1.7.0-update45_b31
ORACLE JRE=1.7.0-update45_b32
ORACLE JRE=1.7.0-update45_b33
ORACLE JRE=1.7.0-update45_b34
ORACLE JRE=1.7.0-update5
ORACLE JRE=1.7.0-update51
ORACLE JRE=1.7.0-update6
ORACLE JRE=1.7.0-update7
ORACLE JRE=1.7.0-update7_b32
ORACLE JRE=1.7.0-update9
ORACLE JRE=1.7.0-update9_b31
ORACLE JRE=1.7.0-update9_b32
Oracle JDK<=1.7.0
ORACLE JRE<=1.7.0

Event History

Nov 18, 2013
Data Sourced
04:17 AM
DescriptionSeverityAffected Software
Dec 29, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2013-4578?

CVE-2013-4578 is classified as a critical vulnerability due to the potential for arbitrary code execution through malicious bytecode injection.

2

How do I fix CVE-2013-4578?

To mitigate CVE-2013-4578, update to the latest version of Oracle JDK or JRE, as the vulnerability has been addressed in subsequent updates.

3

What versions of software are affected by CVE-2013-4578?

CVE-2013-4578 affects various versions of Oracle JDK and JRE 1.7.0 up to update 51.

4

Can CVE-2013-4578 be exploited remotely?

Yes, CVE-2013-4578 can be exploited remotely if the vulnerable software is deployed in an environment that treats untrusted content as trusted.

5

What are the potential impacts of CVE-2013-4578?

The exploitation of CVE-2013-4578 can lead to unauthorized access and control over affected systems, resulting in data breaches or service disruptions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203