PT-2014-2996 · Ibm+6 · Icu Layout Engine+10
Tomas Hoger
·
Published
2014-01-15
·
Updated
2024-06-15
·
CVE-2013-5907
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Java SE versions 5.0u55, 6u65, and 7u45
JRockit versions R27.7.7 and R28.2.9
Java SE Embedded version 7u45
OpenJDK version 7
Description
The issue affects confidentiality, integrity, and availability via unknown vectors related to 2D. It is reportedly due to incorrect input validation in the ICU Layout Engine, which allows attackers to cause a denial of service or possibly execute arbitrary code via a crafted font file.
Recommendations
For Oracle Java SE versions 5.0u55, 6u65, and 7u45, update to a version that is not affected by this issue.
For JRockit versions R27.7.7 and R28.2.9, update to a version that is not affected by this issue.
For Java SE Embedded version 7u45, update to a version that is not affected by this issue.
For OpenJDK version 7, update to a version that is not affected by this issue.
As a temporary workaround, consider disabling the use of crafted font files to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Hp-Ux
Ibm Aix
Icu Layout Engine
Jrockit
Java Platform
Java Se Embedded
Openjdk
Oracle Java Se
Red Hat
Suse