HIGH · 10.0

CVE-2013-1493

The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitr...

Vulnerability Description

The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
OracleJre<= 1.7.0
SunJre1.5.0
OracleJdk<= 1.6.0
SunJdk1.6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-1493?

CVE-2013-1493 is a vulnerability with a CVSS score of 10.0 (HIGH). The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitr...

How severe is CVE-2013-1493?

CVE-2013-1493 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-1493?

Check the references section above for vendor advisories and patch information. Affected products include: Oracle Jre, Sun Jre, Oracle Jdk, Sun Jdk.