CVE-2013-1493

High PUBLISHED

The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40...

Oracle · Java SE

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
10.0 High

At a Glance

The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.

java metasploit
CVE Published
Mar 04, 2013
Exploitation Reported
Mar 04, 2013
CVSS
10.0 High
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • openSUSE-SU-2013:0438 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00012...
  • GLSA-201406-32 security.gentoo.org · Vendor Advisory http://security.gentoo.org/glsa/glsa-201406-32.xml
  • MDVSA-2013:095 mandriva.com · Vendor Advisory http://www.mandriva.com/security/advisories?name=MDVSA-2013:095
  • SSRT101156 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=136570436423916&w=2
  • RHSA-2013:0604 rhn.redhat.com · Vendor Advisory http://rhn.redhat.com/errata/RHSA-2013-0604.html
Show 26 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.