PT-2013-1345 · Oracle+2 · Java Se+4

Publicado

2013-04-17

·

Atualizado

2025-03-13

·

CVE-2013-2423

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Java SE versions prior to 7 Update 17 OpenJDK 7
Description The issue affects the integrity of the system, potentially allowing remote attackers to bypass permission checks and modify arbitrary public final fields using reflection and type confusion. This could be achieved by exploiting an unspecified vulnerability in the Java Runtime Environment component related to HotSpot. The vulnerability may also be caused by a buffer overflow in memory, which could allow a remote attacker to influence integrity or disable the security manager.
Recommendations For Java SE versions prior to 7 Update 17, update to a version later than 7 Update 17 to resolve the issue. For OpenJDK 7, consider disabling the use of the MethodHandles method and restricting reflection to minimize the risk of exploitation until a patch is available. As a temporary workaround, consider restricting access to the HotSpot component to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-03796
CESA-2013_0751
CVE-2013-2423
OPENSUSE-SU-2024:10534-1
RHSA-2013:0751
RHSA-2013:0752
RHSA-2013:0757
RHSA-2013:0822
RHSA-2013_0751
RHSA-2013_0752
RHSA-2013_0757
RHSA-2013_0822

Produtos afetados

Centos
Java Platform
Java Se
Openjdk
Red Hat