Description
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to insufficient "validation of images" in share/native/sun/awt/image/awt_ImageRep.c, possibly involving offsets.
Published: 2013-04-17
Score: 10.0 Critical
EPSS: 6.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2013-2366 Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to insufficient "validation of images" in share/native/sun/awt/image/awt_ImageRep.c, possibly involving offsets.
Ubuntu USN Ubuntu USN USN-1806-1 OpenJDK 7 vulnerabilities
Ubuntu USN Ubuntu USN USN-1819-1 OpenJDK 6 vulnerabilities
References
Link Providers
http://blog.fuseyism.com/index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released/ cve-icon cve-icon
http://blog.fuseyism.com/index.php/2013/04/25/security-icedtea-1-11-11-1-12-5-for-openjdk-6-released/ cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880 cve-icon cve-icon
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/cf93d3828aa8 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2013/Apr/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00007.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00013.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00007.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-updates/2013-05/msg00017.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-updates/2013-06/msg00099.html cve-icon cve-icon
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022796.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=137283787217316&w=2 cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0752.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0757.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0758.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-1455.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-1456.html cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-201406-32.xml cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2013:145 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2013:161 cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html cve-icon cve-icon
http://www.securityfocus.com/bid/59167 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-1806-1 cve-icon cve-icon
http://www.us-cert.gov/ncas/alerts/TA13-107A cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=952638 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2013-2420 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16597 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19354 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19704 cve-icon cve-icon
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0124 cve-icon cve-icon
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0130 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2013-2420 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2024-08-06T15:36:46.488Z

Reserved: 2013-03-05T00:00:00.000Z

Link: CVE-2013-2420

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2013-04-17T18:55:07.017

Modified: 2026-04-29T01:13:23.040

Link: CVE-2013-2420

cve-icon Redhat

Severity : Critical

Publid Date: 2013-04-16T00:00:00Z

Links: CVE-2013-2420 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses