CVE-2013-1491

HIGH

Description

The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to execute arbitrary code via vectors related to 2D, as demonstrated by Joshua Drake during a Pwn2Own competition at CanSecWest 2013.

References

http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880

http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157

http://lists.apple.com/archives/security-announce/2013/Apr/msg00001.html

http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00013.html

http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00001.html

http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00007.html

http://marc.info/?l=bugtraq&m=137283787217316&w=2

http://rhn.redhat.com/errata/RHSA-2013-0757.html

http://rhn.redhat.com/errata/RHSA-2013-0758.html

http://rhn.redhat.com/errata/RHSA-2013-1455.html

http://rhn.redhat.com/errata/RHSA-2013-1456.html

http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html

http://www.us-cert.gov/ncas/alerts/TA13-107A

http://www.zdnet.com/pwn2own-down-go-all-the-browsers-7000012283/

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16663

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19482

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19553

https://twitter.com/thezdi/status/309438311112507392

Details

Source: MITRE

Published: 2013-03-08

Updated: 2017-09-19

Type: CWE-94

Risk Information

CVSS v2.0

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH

Tenable Plugins

View all (24 total)

IDNameProductFamilySeverity
78976RHEL 5 / 6 : IBM Java Runtime in Satellite Server (RHSA-2013:1456) (ROBOT)NessusRed Hat Local Security Checks
critical
78975RHEL 5 / 6 : IBM Java Runtime in Satellite Server (RHSA-2013:1455) (BEAST) (ROBOT)NessusRed Hat Local Security Checks
critical
72139GLSA-201401-30 : Oracle JRE/JDK: Multiple vulnerabilities (ROBOT)NessusGentoo Local Security Checks
critical
71861IBM Domino 9.x < 9.0.1 Multiple Vulnerabilities (credentialed check)NessusWindows
critical
71859IBM Domino 9.x < 9.0.1 Multiple Vulnerabilities (uncredentialed check)NessusMisc.
critical
70744IBM Notes 8.5.x < 8.5.3 FP5 Multiple VulnerabilitiesNessusWindows
critical
70743IBM Domino 8.5.x < 8.5.3 FP5 Multiple VulnerabilitiesNessusWindows
critical
70742IBM Domino 8.5.x < 8.5.3 FP 5 Multiple VulnerabilitiesNessusMisc.
critical
66857SuSE 10 Security Update : Java 1.5.0 (ZYPP Patch Number 8593)NessusSuSE Local Security Checks
critical
66856SuSE 10 Security Update : Java 1.4.2 (ZYPP Patch Number 8601)NessusSuSE Local Security Checks
critical
66855SuSE 11.2 / 11.3 Security Update : IBM Java 1.7.0 / IBM Java (SAT Patch Numbers 7794 / 7921)NessusSuSE Local Security Checks
critical
66854SuSE 11.2 Security Update : Java 1.4.2 (SAT Patch Number 7793)NessusSuSE Local Security Checks
critical
66618SuSE 10 Security Update : IBM Java (ZYPP Patch Number 8582)NessusSuSE Local Security Checks
critical
66616SuSE 11.2 / 11.3 Security Update : IBM Java (SAT Patch Numbers 7744 / 7920)NessusSuSE Local Security Checks
critical
66550RHEL 5 / 6 : java-1.5.0-ibm (RHSA-2013:0855)NessusRed Hat Local Security Checks
critical
66440RHEL 5 / 6 : java-1.6.0-ibm (RHSA-2013:0823)NessusRed Hat Local Security Checks
critical
66439RHEL 5 / 6 : java-1.7.0-ibm (RHSA-2013:0822)NessusRed Hat Local Security Checks
critical
66030RHEL 5 / 6 : java-1.6.0-sun (RHSA-2013:0758)NessusRed Hat Local Security Checks
critical
66029RHEL 5 / 6 : java-1.7.0-oracle (RHSA-2013:0757)NessusRed Hat Local Security Checks
critical
6761Oracle Java JDK / JRE / SE Multiple Vulnerabilities (April 2013 CPU)Nessus Network MonitorWeb Clients
critical
65999Mac OS X : Java for OS X 2013-003NessusMacOS X Local Security Checks
critical
65998Mac OS X : Java for Mac OS X 10.6 Update 15NessusMacOS X Local Security Checks
critical
65996Oracle Java SE Multiple Vulnerabilities (April 2013 CPU) (Unix)NessusMisc.
critical
65995Oracle Java SE Multiple Vulnerabilities (April 2013 CPU)NessusWindows
critical