CVE-2013-1493
published 2013-03-05CVE-2013-1493: The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier…
PriorityP183critical10CVSS 2.0
AVNACLAuNCCICAC
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
86.15%
99.7th percentile
The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | <= 1.6.0 | — |
| oracle | jdk | <= 1.5.0 | — |
| oracle | jdk | <= 1.7.0 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | <= 1.6.0 | — |
| oracle | jre | <= 1.5.0 | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2013-1493 exploit delivers a malicious JAR containing specific class files: Init.class (name randomized at runtime), Leak.class, MyBufferedImage.class, and MyColorSpace.class — detection should look for JARs containing this combination of Color Management class names. ↗
- →The exploit abuses Java Color Management (CMM) classes to escape the sandbox; process trees showing java.exe or javaw.exe spawning unexpected child processes following applet loading are indicative of successful exploitation. ↗
- →The exploit requires user acceptance of a Java security warning (does not bypass click-to-play); social engineering lure pages with 'Loading, Please Wait...' text should be flagged. ↗
- ·The Metasploit module randomizes the 'Init' class name and also randomizes the strings 'metasploit' and 'Payload' within JAR entries at runtime, reducing the reliability of static string-based signatures against this class name. ↗
- ·The vulnerability affects Java 7 Update 15 and earlier and Java 6 Update 41 and earlier; Java 7 Update 17 and Java 6 Update 43 contain the fix — detections targeting unpatched versions should scope to these version ranges. ↗
- ·The exploit is cross-platform (Windows, Mac, Linux) due to Java's cross-platform nature, so detection should not be scoped to Windows only. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2013-03-07·CVSS 10.0
CVE-2013-0809 [CRITICAL] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: OpenJDK could be made to crash or run programs as your login if it opened a
specially crafted file.
USN-1755-1 fixed vulnerabilities in OpenJDK 6. This update provides the
corresponding updates for OpenJDK 7.
Original advisory details:
It was discovered that OpenJDK did not properly validate certain types
of images. A remote attacker could exploit this to cause OpenJDK to crash.
(CVE-2013-0809)
It was discovered that OpenJDK did not properly check return values when
performing color conversion for images. If a user were tricked into
opening a crafted image with OpenJDK, such as with the Java plugin, a
remote attacker could cause OpenJDK to crash or execute arbitrary code
outside of the Java sandbox with the privileges of the user invoking the
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2013-03-05·CVSS 10.0
CVE-2013-0809 [CRITICAL] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: OpenJDK could be made to crash or run programs as your login if it opened a
specially crafted file.
It was discovered that OpenJDK did not properly validate certain types
of images. A remote attacker could exploit this to cause OpenJDK to crash.
(CVE-2013-0809)
It was discovered that OpenJDK did not properly check return values when
performing color conversion for images. If a user were tricked into
opening a crafted image with OpenJDK, such as with the Java plugin, a
remote attacker could cause OpenJDK to crash or execute arbitrary code
outside of the Java sandbox with the privileges of the user invoking the
program. (CVE-2013-1493)
Instructions: After a standard system update you need to restart any applications using
OpenJDK, such as your br
Red Hat
OpenJDK: Specially crafted sample model integer overflow (2D, 8007014)
vendor_redhat·2013-03-04·CVSS 10.0
CVE-2013-0809 [CRITICAL] CWE-190 OpenJDK: Specially crafted sample model integer overflow (2D, 8007014)
OpenJDK: Specially crafted sample model integer overflow (2D, 8007014)
Unspecified vulnerability in the 2D component in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-1493.
Red Hat
OpenJDK: CMM malformed raster memory corruption (2D, 8007675)
vendor_redhat·2013-03-04·CVSS 10.0
CVE-2013-1493 [CRITICAL] OpenJDK: CMM malformed raster memory corruption (2D, 8007675)
OpenJDK: CMM malformed raster memory corruption (2D, 8007675)
The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.
GHSA
GHSA-qv6m-9ccr-3jxp: Unspecified vulnerability in the 2D component in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 a
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2013-0809 [CRITICAL] GHSA-qv6m-9ccr-3jxp: Unspecified vulnerability in the 2D component in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 a
Unspecified vulnerability in the 2D component in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-1493.
GHSA
GHSA-v3wr-hv3w-x2rj: The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5
ghsa_unreviewed·2022-05-14
CVE-2013-1493 [HIGH] CWE-119 GHSA-v3wr-hv3w-x2rj: The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5
The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.
VulnCheck
Oracle Java Runtime Environment (JRE) Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2013·CVSS 10.0
CVE-2013-1493 [CRITICAL] Oracle Java Runtime Environment (JRE) Improper Restriction of Operations within the Bounds of a Memory Buffer
Oracle Java Runtime Environment (JRE) Improper Restriction of Operations within the Bounds of a Memory Buffer
The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.
Affected: Oracle Java Runtime Environment (JRE)
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https:/
No detection rules found.
Exploit-DB
Java CMM - Remote Code Execution (Metasploit)
exploitdb·2013-03-29
CVE-2013-1493 Java CMM - Remote Code Execution (Metasploit)
Java CMM - Remote Code Execution (Metasploit)
---
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# web site for more information on licensing and terms of use.
# http://metasploit.com/
##
require 'msf/core'
require 'rex'
class Metasploit3 false })
def initialize( info = {} )
super( update_info( info,
'Name' => 'Java CMM Remote Code Execution',
'Description' => %q{
This module abuses the Color Management classes from a Java Applet to run
arbitrary Java code outside of the sandbox as exploited in the wild in February
and March of 2013. The vulnerability affects Java version 7u15 and earlier and 6u41
and earlier and has been tested successfully on Windows XP SP3 and Windows 7 SP1
systems. T
Metasploit
Java CMM Remote Code Execution
metasploit
Java CMM Remote Code Execution
Java CMM Remote Code Execution
This module abuses the Color Management classes from a Java Applet to run arbitrary Java code outside of the sandbox as exploited in the wild in February and March of 2013. The vulnerability affects Java version 7u15 and earlier and 6u41 and earlier and has been tested successfully on Windows XP SP3 and Windows 7 SP1 systems. This exploit doesn't bypass click-to-play, so the user must accept the java warning in order to run the malicious applet.
Qualys
Assess Your Risk From Ransomware Attacks, Powered by Qualys Research
blogs_qualys·2021-10-05
Assess Your Risk From Ransomware Attacks, Powered by Qualys Research
## Table of Contents
Clear guidelines from authorities for ransomware prevention
Qualys undertakes research on ransomware to deliver actionable insights
Challenges in following guidelines for preventing ransomware attacks
Assess & continuously monitor your ransomware risk, powered by Qualys Research
Learn more and see for yourself
Resources
References
Ransomware attacks are among the most significant cyber threats facing businesses today. Recent warnings about Conti ransomware, issued by a joint cybersecurity advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), FBI and National Security Agency, are a strong signal that ransomware attacks are becoming even more sophisticated and massive via the ransomware-as-a-service operating model. This new model allows
Krebs
Styx Exploit Pack: Domo Arigato, PC Roboto
blogs_krebs·2013-07-08
Styx Exploit Pack: Domo Arigato, PC Roboto
Not long ago, miscreants who wanted to buy an exploit kit — automated software that helps booby-trap hacked sites to deploy malicious code — had to be fairly well-connected, or at least have access to semi-private underground forums. These days, some exploit kit makers are brazenly advertising and offering their services out in the open, marketing their wares as browser vulnerability “stress-test platforms.”
Styx Pack victims, by browser and OS version.
Aptly named after the river in Greek mythology that separates mere mortals from the underworld, the Styx exploit pack is a high-end software package that is made for the underground but marketed and serviced at the public styx-crypt[dot]com. The purveyors of this malware-as-a-service also have made a 24 hour virtual help desk available to
Krebs
Styx Exploit Pack: Domo Arigato, PC Roboto – Krebs on Security
blogs_krebs·2013-07-01
Styx Exploit Pack: Domo Arigato, PC Roboto – Krebs on Security
Not long ago, miscreants who wanted to buy an exploit kit — automated software that helps booby-trap hacked sites to deploy malicious code — had to be fairly well-connected, or at least have access to semi-private underground forums. These days, some exploit kit makers are brazenly advertising and offering their services out in the open, marketing their wares as browser vulnerability “stress-test platforms.”
Styx Pack victims, by browser and OS version.
Aptly named after the river in Greek mythology that separates mere mortals from the underworld, the Styx exploit pack is a high-end software package that is made for the underground but marketed and serviced at the public styx-crypt[dot]com . The purveyors of this malware-as-a-service also have made a 24 hour virtual help desk available t
Krebs
Oracle Issues Emergency Java Update
blogs_krebs·2013-03-04·CVSS 10.0
CVE-2013-1493 [CRITICAL] Oracle Issues Emergency Java Update
Oracle today pushed out the third update in less than a month to fix critical vulnerabilities in its Java software. This patch plugs a dangerous security hole in Java that attackers have been exploiting to break into systems.
Java 7 Update 17 and Java 6 Update 43 address a critical vulnerability (CVE-2013-1493) in Java that security experts warned last week was being used in targeted attacks against high-profile targets. Oracle had intended to quit shipping updates for Java 6 at the end of February, but apparently reversed course for the time being to help Java 6 users address this latest crisis.
I thought this was unusually speedy patch response for Oracle, that is until I read an Oracle blog post that accompanied the patch release. Oracle said that while reports of active exploitation
Krebs
Oracle Issues Emergency Java Update – Krebs on Security
blogs_krebs·2013-03-01·CVSS 10.0
CVE-2013-1493 [CRITICAL] Oracle Issues Emergency Java Update – Krebs on Security
Oracle today pushed out the third update in less than a month to fix critical vulnerabilities in its Java software. This patch plugs a dangerous security hole in Java that attackers have been exploiting to break into systems.
Java 7 Update 17 and Java 6 Update 43 address a critical vulnerability (CVE-2013-1493) in Java that security experts warned last week was being used in targeted attacks against high-profile targets. Oracle had intended to quit shipping updates for Java 6 at the end of February, but apparently reversed course for the time being to help Java 6 users address this latest crisis.
I thought this was unusually speedy patch response for Oracle, that is until I read an Oracle blog post that accompanied the patch release. Oracle said that while reports of active exploitation
Recorded Future
Visualizing RedKit Exploits
blogs_recorded_future·CVSS 7.8
[HIGH] Visualizing RedKit Exploits
## Visualizing RedKit Exploits
The private but popular RedKit exploit kit appears to be experiencing a resurgence based on a report by Kahu Security. Initially spotted back in May 2012 , the exploit kit drew attention after cybercriminals used it in drive-by-download attacks from NBC’s compromised website in January 2013 and spam campaigns immediately after the Boston Marathon bombings .
These attacks featured iframes on the compromised websites performing simultaneous actions when rendered in a victim’s web browser. The exploit kit competes against and leverages some of the same exploits as CritXPack, Gong Da, Nuclear Pack, Cool, and Blackhole 2.0. Monitoring developments and adoption of RedKit may be of particular interest given the recent arrest in Russia of Blackhole’s creator .
Cyb
Recorded Future
Visualizing RedKit Exploits
blogs_recorded_future·CVSS 7.8
[HIGH] Visualizing RedKit Exploits
# Visualizing RedKit Exploits
The private but popular RedKit exploit kit appears to be experiencing a resurgence based on a report by Kahu Security. Initially spotted back in May 2012, the exploit kit drew attention after cybercriminals used it in drive-by-download attacks from NBC’s compromised website in January 2013 and spam campaigns immediately after the Boston Marathon bombings.
These attacks featured iframes on the compromised websites performing simultaneous actions when rendered in a victim’s web browser. The exploit kit competes against and leverages some of the same exploits as CritXPack, Gong Da, Nuclear Pack, Cool, and Blackhole 2.0. Monitoring developments and adoption of RedKit may be of particular interest given the recent arrest in Russia of Blackhole’s creator.
Cybercr
arXiv
MalCVE: Malware Detection and CVE Association Using Large Language Models
arxiv_fulltext·2026-02-02
MalCVE: Malware Detection and CVE Association Using Large Language Models
MalCVE: Malware Detection and CVE Association
Using Large Language Models
Eduard Andrei Cristea
Norwegian University of Science and Technology
Trondheim
Norway
[email protected]
Petter Molnes
Norwegian University of Science and Technology
Trondheim
Norway
[email protected]
Jingyue Li
Norwegian University of Science and Technology
Trondheim
Norway
[email protected]
Cristea, Molnes, and Li
## Abstract
Malicious software attacks are having an increasingly significant economic impact. Commercial malware detection software can be costly, and tools that attribute malware to the specific software vulnerabilities it exploits are largely lacking. Understanding the connection between malware and the vulnerabilities it targets is crucial for analyzing past threats and proactively defending
Bugzilla
CVE-2013-1493 OpenJDK: CMM malformed raster memory corruption (2D, 8007675)
bugzilla·2013-03-04·CVSS 10.0
CVE-2013-1493 [CRITICAL] CVE-2013-1493 OpenJDK: CMM malformed raster memory corruption (2D, 8007675)
CVE-2013-1493 OpenJDK: CMM malformed raster memory corruption (2D, 8007675)
It was discovered that the CMM part of the 2D component did not properly reject certain malformed images. Specially-crafted raster parameters could cause Java Virtual Machine memory corruption and, possibly, lead to arbitrary code execution with the virtual machine privileges.
Discussion:
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-1493 to
the following vulnerability:
Name: CVE-2013-1493
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1493
Assigned: 20130130
Reference: http://blog.fireeye.com/research/2013/02/yaj0-yet-another-java-zero-day-2.html
Reference: http://www.symantec.com/connect/blogs/latest-java-zero-day-shares-connections-bit9-security-incident
Reference: https:/
Bugzilla
CVE-2013-0809 OpenJDK: Specially crafted sample model integer overflow (2D, 8007014)
bugzilla·2013-03-04·CVSS 10.0
CVE-2013-0809 [CRITICAL] CVE-2013-0809 OpenJDK: Specially crafted sample model integer overflow (2D, 8007014)
CVE-2013-0809 OpenJDK: Specially crafted sample model integer overflow (2D, 8007014)
An integer overflow flaw was found in the way the 2D component handled certain sample model instances. A specially-crafted sample model instance could cause Java Virtual Machine memory corruption and, possibly, lead to arbitrary code execution with the virtual machine privileges.
Discussion:
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-0809 to
the following vulnerability:
Name: CVE-2013-0809
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0809
Assigned: 20130105
Reference: http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1915099.xml
Unspecified vulnerability in the 2D component in the Java Runtime
Environment (JRE) component in Oracle Java SE 7 Upd
http://blog.fireeye.com/research/2013/02/yaj0-yet-another-java-zero-day-2.htmlhttp://h20565.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04117626-1http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-03/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-03/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00020.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-March/022145.htmlhttp://marc.info/?l=bugtraq&m=136439120408139&w=2http://marc.info/?l=bugtraq&m=136570436423916&w=2http://rhn.redhat.com/errata/RHSA-2013-0601.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0603.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0604.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.exploit-db.com/exploits/24904http://www.kb.cert.org/vuls/id/688246http://www.mandriva.com/security/advisories?name=MDVSA-2013:095http://www.oracle.com/ocom/groups/public/%40otn/documents/webcontent/1915099.xmlhttp://www.oracle.com/technetwork/topics/security/alert-cve-2013-1493-1915081.htmlhttp://www.securityfocus.com/bid/58238http://www.securitytracker.com/id/1029803http://www.symantec.com/connect/blogs/latest-java-zero-day-shares-connections-bit9-security-incidenthttp://www.ubuntu.com/usn/USN-1755-2http://www.us-cert.gov/ncas/alerts/TA13-064Ahttps://bugzilla.redhat.com/show_bug.cgi?id=917553https://krebsonsecurity.com/2013/03/new-java-0-day-attack-echoes-bit9-breach/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19246https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19477https://twitter.com/jduck1337/status/307629902574800897https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0088http://blog.fireeye.com/research/2013/02/yaj0-yet-another-java-zero-day-2.htmlhttp://h20565.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c04117626-1http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-03/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-03/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-04/msg00020.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-March/022145.htmlhttp://marc.info/?l=bugtraq&m=136439120408139&w=2http://marc.info/?l=bugtraq&m=136570436423916&w=2http://rhn.redhat.com/errata/RHSA-2013-0601.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0603.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0604.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.exploit-db.com/exploits/24904http://www.kb.cert.org/vuls/id/688246http://www.mandriva.com/security/advisories?name=MDVSA-2013:095http://www.oracle.com/ocom/groups/public/%40otn/documents/webcontent/1915099.xmlhttp://www.oracle.com/technetwork/topics/security/alert-cve-2013-1493-1915081.htmlhttp://www.securityfocus.com/bid/58238http://www.securitytracker.com/id/1029803http://www.symantec.com/connect/blogs/latest-java-zero-day-shares-connections-bit9-security-incidenthttp://www.ubuntu.com/usn/USN-1755-2http://www.us-cert.gov/ncas/alerts/TA13-064Ahttps://bugzilla.redhat.com/show_bug.cgi?id=917553https://krebsonsecurity.com/2013/03/new-java-0-day-attack-echoes-bit9-breach/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19246https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19477https://twitter.com/jduck1337/status/307629902574800897https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0088
2013-03-05
Published
Exploited in the wild