CVE-2013-5803: Low severity oracle java se vulnerability
It was discovered that KRB5 / Kerberos implementation in OpenJDK did not properly parse KDC (Kerberos Key Distribution Center) responses. A malformed or truncated packet could cause a Java application using JGSS to exit because of an unexpected exception.
Other sources
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via vectors related to JGSS.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5803?
CVE-2013-5803 has been classified as a moderate severity vulnerability.
How do I fix CVE-2013-5803?
To fix CVE-2013-5803, update your OpenJDK or IcedTea package to the recommended versions or later.
What applications are impacted by CVE-2013-5803?
CVE-2013-5803 affects Java applications using JGSS that are dependent on the KRB5/Kerberos implementation in OpenJDK.
What kind of attack can exploit CVE-2013-5803?
An attacker can exploit CVE-2013-5803 by sending a malformed or truncated packet, causing a Java application to exit unexpectedly.
Is there a workaround for CVE-2013-5803?
Currently, the best practice is to apply updates for affected applications rather than relying on workarounds.