CVE-2013-5778: Medium severity oracle jre vulnerability
It was discovered that AWT component's native ImagingLib failed to properly check image boundaries when preforming image conversion. An untrusted Java application or applet could possibly use this flaw to bypass certain Java sandbox restrictions by reading portions of the JVM memory.
Other sources
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, 6u60 and earlier, 5.0u51 and earlier, and Embedded 7u40 and earlier allows remote attackers to affect confidentiality via unknown vectors related to 2D.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5778?
CVE-2013-5778 is considered to have a moderate severity due to its potential to allow untrusted Java applications to read JVM memory.
How do I fix CVE-2013-5778?
To fix CVE-2013-5778, you should update to the latest version of the affected software, specifically IcedTea versions 1.12.7, 1.11.14, or 2.4.3.
Which software is affected by CVE-2013-5778?
CVE-2013-5778 affects various versions of Oracle JRE, Oracle JDK, and Sun JRE, particularly versions 1.5.0 through 1.7.0.
Can CVE-2013-5778 be exploited remotely?
Yes, CVE-2013-5778 can potentially be exploited remotely by untrusted Java applications or applets.
What impact does CVE-2013-5778 have on system security?
The impact of CVE-2013-5778 includes the possibility of unauthorized memory access, potentially leading to sensitive information disclosure or further exploitation.