[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-0401Date: (C)2013-03-15   (M)2023-12-22


The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to execute arbitrary code via vectors related to AWT, as demonstrated by Ben Murphy during a Pwn2Own competition at CanSecWest 2013. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to invocation of the system class loader by the sun.awt.datatransfer.ClassLoaderObjectInputStream class, which allows remote attackers to bypass Java sandbox restrictions.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 10.0
Exploit Score: 10.0
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
GLSA-201406-32
MDVSA-2013:145
MDVSA-2013:161
RHSA-2013:0752
RHSA-2013:0757
RHSA-2013:0758
RHSA-2013:1455
RHSA-2013:1456
SSRT101252
SSRT101305
SUSE-SU-2013:0814
SUSE-SU-2013:0835
SUSE-SU-2013:0871
TA13-107A
USN-1806-1
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022796.html
http://blog.fuseyism.com/index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released/
http://blog.fuseyism.com/index.php/2013/04/25/security-icedtea-1-11-11-1-12-5-for-openjdk-6-released/
http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/31c782610044
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html
http://www.zdnet.com/pwn2own-down-go-all-the-browsers-7000012283/
https://bugzilla.redhat.com/show_bug.cgi?id=920245
https://twitter.com/thezdi/status/309784608508100608
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0124
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0130
openSUSE-SU-2013:0777
openSUSE-SU-2013:0964
oval:org.mitre.oval:def:16297
oval:org.mitre.oval:def:19463
oval:org.mitre.oval:def:19641

CPE    2
cpe:/a:oracle:jdk:1.7.0:update17
cpe:/a:oracle:jre:1.7.0:update17
CWE    1
CWE-94
OVAL    24
oval:org.secpod.oval:def:1300183
oval:org.secpod.oval:def:1600284
oval:org.secpod.oval:def:701275
oval:org.secpod.oval:def:1600281
...

© SecPod Technologies