CVE-2013-5804: Medium severity oracle jre vulnerability

Published Oct 15, 2013
·
Updated

It was discovered that javac did not properly ignore certain ignorable characters. An attacker could influence the integrity and confidentiality of a system by providing specially crafted input, which is then used by javadoc to generate API documentation.

Upstream reports that this issue is relevant to uses where javadoc is used to generate documentation for an untrusted source code and have it hosted on a domain not controlled by the author of the source code (the attacker).

Other sources

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, and JRockit R27.7.6 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Javadoc.

MITRE

Affected Software

202 affected componentsFixes available
redhat/icedtea<2.4.3
2.4.3
redhat/icedtea<1.11.14
1.11.14
redhat/icedtea<1.12.7
1.12.7
Oracle JRE<=1.7.0
Oracle JRE=1.7.0
Oracle JRE=1.7.0-update1
Oracle JRE=1.7.0-update10
Oracle JRE=1.7.0-update11
Oracle JRE=1.7.0-update13
Oracle JRE=1.7.0-update15
Oracle JRE=1.7.0-update17
Oracle JRE=1.7.0-update2
Oracle JRE=1.7.0-update21
Oracle JRE=1.7.0-update25
Oracle JRE=1.7.0-update3
Oracle JRE=1.7.0-update4
Oracle JRE=1.7.0-update5
Oracle JRE=1.7.0-update6
Oracle JRE=1.7.0-update7
Oracle JRE=1.7.0-update9
Oracle JRE<=1.6.0
Oracle JRE=1.6.0-update22
Oracle JRE=1.6.0-update23
Oracle JRE=1.6.0-update24
Oracle JRE=1.6.0-update25
Oracle JRE=1.6.0-update26
Oracle JRE=1.6.0-update27
Oracle JRE=1.6.0-update29
Oracle JRE=1.6.0-update30
Oracle JRE=1.6.0-update31
Oracle JRE=1.6.0-update32
Oracle JRE=1.6.0-update33
Oracle JRE=1.6.0-update34
Oracle JRE=1.6.0-update35
Oracle JRE=1.6.0-update37
Oracle JRE=1.6.0-update38
Oracle JRE=1.6.0-update39
Oracle JRE=1.6.0-update41
Oracle JRE=1.6.0-update43
Oracle JRE=1.6.0-update45
Oracle JRE=1.6.0-update51
Sun JRE=1.6.0
Sun JRE=1.6.0-update_1
Sun JRE=1.6.0-update_10
Sun JRE=1.6.0-update_11
Sun JRE=1.6.0-update_12
Sun JRE=1.6.0-update_13
Sun JRE=1.6.0-update_14
Sun JRE=1.6.0-update_15
Sun JRE=1.6.0-update_16
Sun JRE=1.6.0-update_17
Sun JRE=1.6.0-update_18
Sun JRE=1.6.0-update_19
Sun JRE=1.6.0-update_2
Sun JRE=1.6.0-update_20
Sun JRE=1.6.0-update_21
Sun JRE=1.6.0-update_3
Sun JRE=1.6.0-update_4
Sun JRE=1.6.0-update_5
Sun JRE=1.6.0-update_6
Sun JRE=1.6.0-update_7
Sun JRE=1.6.0-update_9
Oracle Jrockit<=r28.2.8
Oracle Jrockit=r28.0.0
Oracle Jrockit=r28.0.1
Oracle Jrockit=r28.0.2
Oracle Jrockit=r28.1.0
Oracle Jrockit=r28.1.1
Oracle Jrockit=r28.1.3
Oracle Jrockit=r28.1.4
Oracle Jrockit=r28.1.5
Oracle Jrockit=r28.2.2
Oracle Jrockit=r28.2.3
Oracle Jrockit=r28.2.4
Oracle Jrockit=r28.2.5
Oracle Jrockit=r28.2.6
Oracle JDK<=1.5.0
Oracle JDK=1.5.0-update36
Oracle JDK=1.5.0-update38
Oracle JDK=1.5.0-update40
Oracle JDK=1.5.0-update41
Oracle JDK=1.5.0-update45
Sun JDK=1.5.0
Sun JDK=1.5.0-update1
Sun JDK=1.5.0-update10
Sun JDK=1.5.0-update11
Sun JDK=1.5.0-update11_b03
Sun JDK=1.5.0-update12
Sun JDK=1.5.0-update13
Sun JDK=1.5.0-update14
Sun JDK=1.5.0-update15
Sun JDK=1.5.0-update16
Sun JDK=1.5.0-update17
Sun JDK=1.5.0-update18
Sun JDK=1.5.0-update19
Sun JDK=1.5.0-update2
Sun JDK=1.5.0-update20
Sun JDK=1.5.0-update21
Sun JDK=1.5.0-update22
Sun JDK=1.5.0-update23
Sun JDK=1.5.0-update24
Sun JDK=1.5.0-update25
Sun JDK=1.5.0-update26
Sun JDK=1.5.0-update27
Sun JDK=1.5.0-update28
Sun JDK=1.5.0-update29
Sun JDK=1.5.0-update3
Sun JDK=1.5.0-update31
Sun JDK=1.5.0-update33
Sun JDK=1.5.0-update4
Sun JDK=1.5.0-update5
Sun JDK=1.5.0-update6
Sun JDK=1.5.0-update7
Sun JDK=1.5.0-update7_b03
Sun JDK=1.5.0-update8
Sun JDK=1.5.0-update9
Oracle JDK<=1.6.0
Oracle JDK=1.6.0-update22
Oracle JDK=1.6.0-update23
Oracle JDK=1.6.0-update24
Oracle JDK=1.6.0-update25
Oracle JDK=1.6.0-update26
Oracle JDK=1.6.0-update27
Oracle JDK=1.6.0-update29
Oracle JDK=1.6.0-update30
Oracle JDK=1.6.0-update31
Oracle JDK=1.6.0-update32
Oracle JDK=1.6.0-update33
Oracle JDK=1.6.0-update34
Oracle JDK=1.6.0-update35
Oracle JDK=1.6.0-update37
Oracle JDK=1.6.0-update38
Oracle JDK=1.6.0-update39
Oracle JDK=1.6.0-update41
Oracle JDK=1.6.0-update43
Oracle JDK=1.6.0-update45
Oracle JDK=1.6.0-update51
Sun JDK=1.6.0
Sun JDK=1.6.0-update_10
Sun JDK=1.6.0-update_11
Sun JDK=1.6.0-update_12
Sun JDK=1.6.0-update_13
Sun JDK=1.6.0-update_14
Sun JDK=1.6.0-update_15
Sun JDK=1.6.0-update_16
Sun JDK=1.6.0-update_17
Sun JDK=1.6.0-update_18
Sun JDK=1.6.0-update_19
Sun JDK=1.6.0-update_20
Sun JDK=1.6.0-update_21
Sun JDK=1.6.0-update_3
Sun JDK=1.6.0-update_4
Sun JDK=1.6.0-update_5
Sun JDK=1.6.0-update_6
Sun JDK=1.6.0-update_7
Sun JDK=1.6.0-update1
Sun JDK=1.6.0-update1_b06
Sun JDK=1.6.0-update2
Oracle JRE<=1.5.0
Oracle JRE=1.5.0-update36
Oracle JRE=1.5.0-update38
Oracle JRE=1.5.0-update40
Oracle JRE=1.5.0-update41
Oracle JRE=1.5.0-update45
Sun JRE=1.5.0
Sun JRE=1.5.0-update1
Sun JRE=1.5.0-update10
Sun JRE=1.5.0-update11
Sun JRE=1.5.0-update12
Sun JRE=1.5.0-update13
Sun JRE=1.5.0-update14
Sun JRE=1.5.0-update15
Sun JRE=1.5.0-update16
Sun JRE=1.5.0-update17
Sun JRE=1.5.0-update18
Sun JRE=1.5.0-update19
Sun JRE=1.5.0-update2
Sun JRE=1.5.0-update20
Sun JRE=1.5.0-update21
Sun JRE=1.5.0-update22
Sun JRE=1.5.0-update23
Sun JRE=1.5.0-update24
Sun JRE=1.5.0-update25
Sun JRE=1.5.0-update26
Sun JRE=1.5.0-update27
Sun JRE=1.5.0-update28
Sun JRE=1.5.0-update29
Sun JRE=1.5.0-update3
Sun JRE=1.5.0-update31
Sun JRE=1.5.0-update33
Sun JRE=1.5.0-update4
Sun JRE=1.5.0-update5
Sun JRE=1.5.0-update6
Sun JRE=1.5.0-update7
Sun JRE=1.5.0-update8
Sun JRE=1.5.0-update9
Oracle Jrockit<=r27.7.6
Oracle Jrockit=r27.7.1
Oracle Jrockit=r27.7.2
Oracle Jrockit=r27.7.3
Oracle Jrockit=r27.7.4
Oracle Jrockit=r27.7.5

Event History

Oct 16, 2013
CVE Published
via MITRE·05:31 PM
Data Sourced
via MITRE·05:31 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2013-5804?

The severity of CVE-2013-5804 is considered moderate, as it could affect the integrity and confidentiality of a system.

2

How do I fix CVE-2013-5804?

To fix CVE-2013-5804, update your Java Runtime Environment (JRE) to versions 1.6.0-update60 or later, or JDK versions 1.6.0-update-51 or later.

3

What systems are affected by CVE-2013-5804?

CVE-2013-5804 affects multiple versions of the Oracle Java Runtime Environment (JRE) and the Oracle JDK, particularly those before 1.7.0-update45.

4

What kind of input is exploited in CVE-2013-5804?

CVE-2013-5804 can be exploited through specially crafted input provided to javac, leading to the generation of insecure API documentation.

5

Is there a patch for CVE-2013-5804?

Yes, patches for CVE-2013-5804 are included in the updates for affected versions of the JDK and JRE listed in the vulnerability advisory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203