CVE-2012-1713
published 2012-06-16CVE-2012-1713: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and…
PriorityP354critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.98%
92.5th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, 1.4.2_37 and earlier, and JavaFX 2.1 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | javafx | <= 2.1 | — |
| oracle | jdk | <= 1.7.0 | — |
| oracle | jdk | <= 1.6.0 | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | <= 1.6.0 | — |
| sun | jdk | <= 1.5.0 | — |
| sun | jdk | <= 1.4.2_37 | — |
| sun | jre | <= 1.5.0 | — |
| sun | jre | <= 1.4.2_37 | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j7wm-898c-h674: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update
ghsa_unreviewed·2022-05-14
CVE-2012-1713 [HIGH] GHSA-j7wm-898c-h674: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, 1.4.2_37 and earlier, and JavaFX 2.1 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
Ubuntu
IcedTea-Web regression
vendor_ubuntu·2012-08-30·CVSS 7.5
[HIGH] IcedTea-Web regression
Title: IcedTea-Web regression
Summary: USN 1505-1 introduced a regression in the IcedTea-Web Java web browser
plugin that prevented it from working with the Chromium web browser.
USN-1505-1 fixed vulnerabilities in OpenJDK 6. As part of the update,
IcedTea-Web packages were upgraded to a new version. That upgrade
introduced a regression which prevented the IcedTea-Web plugin from
working with the Chromium web browser in Ubuntu 11.04 and Ubuntu 11.10.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that multiple flaws existed in the CORBA (Common
Object Request Broker Architecture) implementation in OpenJDK. An
attacker could create a Java application or applet that used these
flaws to bypass Java sandbox restrictions or m
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2012-07-13·CVSS 7.5
CVE-2012-1711 [HIGH] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
It was discovered that multiple flaws existed in the CORBA (Common
Object Request Broker Architecture) implementation in OpenJDK. An
attacker could create a Java application or applet that used these
flaws to bypass Java sandbox restrictions or modify immutable object
data. (CVE-2012-1711, CVE-2012-1719)
It was discovered that multiple flaws existed in the OpenJDK font
manager's layout lookup implementation. A attacker could specially
craft a font file that could cause a denial of service through
crashing the JVM (Java Virtual Machine) or possibly execute arbitrary
code. (CVE-2012-1713)
It was discovered that the SynthLookAndFeel class from Swing in
OpenJDK did not properly prevent access to cert
Red Hat
OpenJDK: fontmanager layout lookup code memory corruption (2D, 7143617)
vendor_redhat·2012-06-12·CVSS 10.0
CVE-2012-1713 [CRITICAL] OpenJDK: fontmanager layout lookup code memory corruption (2D, 7143617)
OpenJDK: fontmanager layout lookup code memory corruption (2D, 7143617)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, 1.4.2_37 and earlier, and JavaFX 2.1 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
Package: java-1.4.2-ibm-sap (Red Hat Enterprise Linux 6) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-5907 ICU: Layout Engine LookupProcessor insufficient input checks (JDK 2D, 8025034)
bugzilla·2014-01-14·CVSS 10.0
CVE-2013-5907 [CRITICAL] CVE-2013-5907 ICU: Layout Engine LookupProcessor insufficient input checks (JDK 2D, 8025034)
CVE-2013-5907 ICU: Layout Engine LookupProcessor insufficient input checks (JDK 2D, 8025034)
An insufficient input validation check flaw was found in the ICU Layout Engine's LookupProcessor, which is part of OpenJDK 2D component. A specially crafted font file could cause Java application to crash or execute arbitrary code. An untrusted Java application or applet could possibly use this flaw to bypass Java sandbox restrictions.
This fix improves checks added in the fix for CVE-2012-1713 (bug 829361).
Discussion:
Public now via Oracle CPU January 2014. Fixed in Oracle JDK 7u51, 6u71 and 5.0u61.
External References:
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-20
Bugzilla
CVE-2012-1713 OpenJDK: fontmanager layout lookup code memory corruption (2D, 7143617)
bugzilla·2012-06-06·CVSS 10.0
CVE-2012-1713 [CRITICAL] CVE-2012-1713 OpenJDK: fontmanager layout lookup code memory corruption (2D, 7143617)
CVE-2012-1713 OpenJDK: fontmanager layout lookup code memory corruption (2D, 7143617)
Multiple flaws were discovered in the native code implementing fontmanager layout lookup operations. A specially-crafted font file could cause Java Virtual Machine to crash or corrupt its memory, possibly allowing code execution with the virtual machine privileges.
Discussion:
Public now via:
http://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.html
Fixed in Oracle Java 7 Update 5 and 6 Update 33.
---
The fix for this issue is or will be included in the following IcedTea versions:
* IcedTea6 1.10.8
* IcedTea6 1.11.3
* IcedTea7 2.1.1
* IcedTea7 2.2.1
IcedTea6 releases announcement:
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.html
http://blog.fuseyism.
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00035.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.htmlhttp://marc.info/?l=bugtraq&m=134496371727681&w=2http://rhn.redhat.com/errata/RHSA-2012-0734.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1243.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://secunia.com/advisories/50659http://secunia.com/advisories/51080http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.ibm.com/support/docview.wss?uid=swg21615246http://www.mandriva.com/security/advisories?name=MDVSA-2012:095http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.htmlhttp://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.htmlhttp://www.securityfocus.com/bid/53946https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16502http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00035.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-June/019076.htmlhttp://marc.info/?l=bugtraq&m=134496371727681&w=2http://rhn.redhat.com/errata/RHSA-2012-0734.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1243.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://secunia.com/advisories/50659http://secunia.com/advisories/51080http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.ibm.com/support/docview.wss?uid=swg21615246http://www.mandriva.com/security/advisories?name=MDVSA-2012:095http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.htmlhttp://www.oracle.com/technetwork/topics/security/javacpujun2012-1515912.htmlhttp://www.securityfocus.com/bid/53946https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16502
2012-06-16
Published