CVE
- Id
- 62367
- CVE No.
- CVE-2013-2420
- Status
- Candidate
- Description
- Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to insufficient "validation of images" in share/native/sun/awt/image/awt_ImageRep.c, possibly involving offsets.
- Phase
- Assigned (20130305)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
623165 | 62367 | CVE-2013-2420 | MLIST:[distro-pkg-dev] 20130417 [SECURITY] IcedTea 1.11.10 for OpenJDK 6 Released! | View |
623166 | 62367 | CVE-2013-2420 | URL:http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022796.html | View |
623167 | 62367 | CVE-2013-2420 | MISC:http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/cf93d3828aa8 | View |
623168 | 62367 | CVE-2013-2420 | MISC:https://bugzilla.redhat.com/show_bug.cgi?id=952638 | View |
623169 | 62367 | CVE-2013-2420 | CONFIRM:http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html | View |
623170 | 62367 | CVE-2013-2420 | CONFIRM:http://blog.fuseyism.com/index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released/ | View |
623171 | 62367 | CVE-2013-2420 | CONFIRM:http://blog.fuseyism.com/index.php/2013/04/25/security-icedtea-1-11-11-1-12-5-for-openjdk-6-released/ | View |
623172 | 62367 | CVE-2013-2420 | CONFIRM:https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0124 | View |
623173 | 62367 | CVE-2013-2420 | CONFIRM:https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0130 | View |
623174 | 62367 | CVE-2013-2420 | APPLE:APPLE-SA-2013-04-16-2 | View |
623175 | 62367 | CVE-2013-2420 | URL:http://lists.apple.com/archives/security-announce/2013/Apr/msg00001.html | View |
623176 | 62367 | CVE-2013-2420 | GENTOO:GLSA-201406-32 | View |
623177 | 62367 | CVE-2013-2420 | URL:http://security.gentoo.org/glsa/glsa-201406-32.xml | View |
623178 | 62367 | CVE-2013-2420 | HP:HPSBUX02889 | View |
623179 | 62367 | CVE-2013-2420 | URL:http://marc.info/?l=bugtraq&m=137283787217316&w=2 | View |
623180 | 62367 | CVE-2013-2420 | HP:SSRT101252 | View |
623181 | 62367 | CVE-2013-2420 | URL:http://marc.info/?l=bugtraq&m=137283787217316&w=2 | View |
623182 | 62367 | CVE-2013-2420 | HP:HPSBUX02922 | View |
623183 | 62367 | CVE-2013-2420 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880 | View |
623184 | 62367 | CVE-2013-2420 | HP:SSRT101305 | View |
623185 | 62367 | CVE-2013-2420 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880 | View |
623186 | 62367 | CVE-2013-2420 | MANDRIVA:MDVSA-2013:145 | View |
623187 | 62367 | CVE-2013-2420 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2013:145 | View |
623188 | 62367 | CVE-2013-2420 | MANDRIVA:MDVSA-2013:161 | View |
623189 | 62367 | CVE-2013-2420 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2013:161 | View |
623190 | 62367 | CVE-2013-2420 | REDHAT:RHSA-2013:0752 | View |
623191 | 62367 | CVE-2013-2420 | URL:http://rhn.redhat.com/errata/RHSA-2013-0752.html | View |
623192 | 62367 | CVE-2013-2420 | REDHAT:RHSA-2013:0757 | View |
623193 | 62367 | CVE-2013-2420 | URL:http://rhn.redhat.com/errata/RHSA-2013-0757.html | View |
623194 | 62367 | CVE-2013-2420 | REDHAT:RHSA-2013:0758 | View |
623195 | 62367 | CVE-2013-2420 | URL:http://rhn.redhat.com/errata/RHSA-2013-0758.html | View |
623196 | 62367 | CVE-2013-2420 | REDHAT:RHSA-2013:1455 | View |
623197 | 62367 | CVE-2013-2420 | URL:http://rhn.redhat.com/errata/RHSA-2013-1455.html | View |
623198 | 62367 | CVE-2013-2420 | REDHAT:RHSA-2013:1456 | View |
623199 | 62367 | CVE-2013-2420 | URL:http://rhn.redhat.com/errata/RHSA-2013-1456.html | View |
623200 | 62367 | CVE-2013-2420 | SUSE:SUSE-SU-2013:0814 | View |
623201 | 62367 | CVE-2013-2420 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00007.html | View |
623202 | 62367 | CVE-2013-2420 | SUSE:openSUSE-SU-2013:0777 | View |
623203 | 62367 | CVE-2013-2420 | URL:http://lists.opensuse.org/opensuse-updates/2013-05/msg00017.html | View |
623204 | 62367 | CVE-2013-2420 | SUSE:SUSE-SU-2013:0835 | View |
623205 | 62367 | CVE-2013-2420 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00013.html | View |
623206 | 62367 | CVE-2013-2420 | SUSE:SUSE-SU-2013:0871 | View |
623207 | 62367 | CVE-2013-2420 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00001.html | View |
623208 | 62367 | CVE-2013-2420 | SUSE:SUSE-SU-2013:0934 | View |
623209 | 62367 | CVE-2013-2420 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00007.html | View |
623210 | 62367 | CVE-2013-2420 | SUSE:openSUSE-SU-2013:0964 | View |
623211 | 62367 | CVE-2013-2420 | URL:http://lists.opensuse.org/opensuse-updates/2013-06/msg00099.html | View |
623212 | 62367 | CVE-2013-2420 | UBUNTU:USN-1806-1 | View |
623213 | 62367 | CVE-2013-2420 | URL:http://www.ubuntu.com/usn/USN-1806-1 | View |
623214 | 62367 | CVE-2013-2420 | CERT:TA13-107A | View |
623215 | 62367 | CVE-2013-2420 | URL:http://www.us-cert.gov/ncas/alerts/TA13-107A | View |
623216 | 62367 | CVE-2013-2420 | OVAL:oval:org.mitre.oval:def:16597 | View |
623217 | 62367 | CVE-2013-2420 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:16597 | View |
623218 | 62367 | CVE-2013-2420 | OVAL:oval:org.mitre.oval:def:19354 | View |
623219 | 62367 | CVE-2013-2420 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:19354 | View |
623220 | 62367 | CVE-2013-2420 | OVAL:oval:org.mitre.oval:def:19704 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
20810 | JVNDB-2013-002385 | Oracle Java SE の Java Runtime Environment における Install の処理に関する脆弱性 | Oracle Java SE の Java Runtime Environment (JRE) には、Install に関する処理に不備があるため、機密性、完全性、可用性に影響のある脆弱性が存在します。 | CVE-2013-2425 | 62367 | 10 | http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-002385.html | View |