Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-1493

Опубликовано: 05 мар. 2013
Источник: ubuntu
Приоритет: high
EPSS Критический
CVSS2: 10

Описание

The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.

РелизСтатусПримечание
devel

not-affected

6b27-1.12.4-1ubuntu1
hardy

released

6b27-1.12.3-0ubuntu1~8.04.2
lucid

released

6b27-1.12.3-0ubuntu1~10.04.1
oneiric

released

6b27-1.12.3-0ubuntu1~11.10.1
precise

released

6b27-1.12.3-0ubuntu1~12.04.1
quantal

released

6b27-1.12.3-0ubuntu1~12.10.1
upstream

pending

6b27-1.12.4

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

DNE

lucid

ignored

end of life
oneiric

ignored

end of life
precise

DNE

quantal

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

released

7u15-2.3.7-1ubuntu2
hardy

DNE

lucid

DNE

oneiric

released

7u15-2.3.7-0ubuntu1~11.10.1
precise

released

7u15-2.3.7-0ubuntu1~12.04.1
quantal

released

7u15-2.3.7-0ubuntu1~12.10.1
upstream

pending

7u15-2.3.8

Показывать по

EPSS

Процентиль: 100%
0.91904
Критический

10 Critical

CVSS2

Связанные уязвимости

redhat
больше 12 лет назад

The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.

nvd
больше 12 лет назад

The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.

debian
больше 12 лет назад

The color management (CMM) functionality in the 2D component in Oracle ...

github
больше 3 лет назад

The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.

oracle-oval
больше 12 лет назад

ELSA-2013-0605: java-1.6.0-openjdk security update (CRITICAL)

EPSS

Процентиль: 100%
0.91904
Критический

10 Critical

CVSS2