CVE-2013-1500
published 2013-06-18CVE-2013-1500: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45…
PriorityP412low3.6CVSS 2.0
AVLACLAuNCPIPAN
EPSS
0.51%
39.7th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality and integrity via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to weak permissions for shared memory.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | <= 1.7.0 | — |
| oracle | jdk | <= 1.6.0 | — |
| oracle | jdk | <= 1.5.0 | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jdk | — | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | <= 1.6.0 | — |
| oracle | jre | <= 1.5.0 | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| oracle | jre | — | — |
| sun | jdk | — | — |
| sun | jdk | — | — |
| sun | jre | — | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
vendor_redhat7.5HIGH
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
webkitgtk: use-after-free vulnerability in the handling of input (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 7.5
CVE-2013-2871 [HIGH] CWE-416 webkitgtk: use-after-free vulnerability in the handling of input (WSA-2015-0001)
webkitgtk: use-after-free vulnerability in the handling of input (WSA-2015-0001)
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of input.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Will not fix
Red Hat
webkitgtk: out-of-bounds read in the SVG implementation (WSA-2015-0001)
vendor_redhat·2015-01-26·CVSS 5.0
CVE-2013-2875 [MEDIUM] CWE-125 webkitgtk: out-of-bounds read in the SVG implementation (WSA-2015-0001)
webkitgtk: out-of-bounds read in the SVG implementation (WSA-2015-0001)
core/rendering/svg/SVGInlineTextBox.cpp in the SVG implementation in Blink, as used in Google Chrome before 28.0.1500.71, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Will not fix
Red Hat
v8: remote DoS or unspecified other impact via type confusion
vendor_redhat·2013-07-30·CVSS 7.5
CVE-2013-2882 [HIGH] v8: remote DoS or unspecified other impact via type confusion
v8: remote DoS or unspecified other impact via type confusion
Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
Package: ruby193-v8 (OpenShift Enterprise 1) - Will not fix
Package: v8 (Red Hat OpenStack Platform 3) - Will not fix
Package: ruby193-v8 (Red Hat OpenStack Platform 4) - Affected
Package: v8 (Red Hat OpenStack Platform 4) - Affected
Package: v8314-v8 (Red Hat Software Collections) - Not affected
Package: ruby193-v8 (Red Hat Subscription Asset Manager) - Will not fix
Package: v8 (Red Hat Subscription Asset Manager) - Will not fix
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2013-07-23·CVSS 3.6
CVE-2013-1500 [LOW] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2013-1500, CVE-2013-2454,
CVE-2013-2458)
A vulnerability was discovered in the OpenJDK Javadoc related to data
integrity. (CVE-2013-1571)
A vulnerability was discovered in the OpenJDK JRE related to information
disclosure and availability. An attacker could exploit this to cause a
denial of service or expose sensitive data over the network.
(CVE-2013-2407)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An attacker could exploit these to expose sensitive
data o
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2013-07-16·CVSS 3.6
CVE-2013-1500 [LOW] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2013-1500, CVE-2013-2454,
CVE-2013-2458)
A vulnerability was discovered in the OpenJDK Javadoc related to data
integrity. (CVE-2013-1571)
A vulnerability was discovered in the OpenJDK JRE related to information
disclosure and availability. An attacker could exploit this to cause a
denial of service or expose sensitive data over the network.
(CVE-2013-2407)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An attacker could exploit these to expose sensitive
data o
Ubuntu
IcedTea Web update
vendor_ubuntu·2013-07-16·CVSS 3.6
CVE-2013-1500 [LOW] IcedTea Web update
Title: IcedTea Web update
Summary: IcedTea Web updated to work with new OpenJDK 7.
USN-1907-1 fixed vulnerabilities in OpenJDK 7. Due to upstream changes,
IcedTea Web needed an update to work with the new OpenJDK 7.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2013-1500, CVE-2013-2454,
CVE-2013-2458)
A vulnerability was discovered in the OpenJDK Javadoc related to data
integrity. (CVE-2013-1571)
A vulnerability was discovered in the OpenJDK JRE related to information
disclosure and availability. An attacker could exploit this to cause a
denial of service or expose sensitive data over the network.
(CVE-2013-2407)
Red Hat
libxml2: Out-of-bounds read via a document that ends abruptly
vendor_redhat·2013-07-09·CVSS 5.0
CVE-2013-2877 [MEDIUM] CWE-125 libxml2: Out-of-bounds read via a document that ends abruptly
libxml2: Out-of-bounds read via a document that ends abruptly
parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to the lack of certain checks for the XML_PARSER_EOF state.
Package: libxml2 (Red Hat Enterprise Linux 5) - Will not fix
Package: mingw32-libxml2 (Red Hat Enterprise Linux 6) - Will not fix
Red Hat
OpenJDK: Insecure shared memory permissions (2D, 8001034)
vendor_redhat·2013-06-18·CVSS 3.6
CVE-2013-1500 [LOW] OpenJDK: Insecure shared memory permissions (2D, 8001034)
OpenJDK: Insecure shared memory permissions (2D, 8001034)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality and integrity via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to weak permissions for shared memory.
GHSA
GHSA-w6m9-3g8m-hgf4: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5
ghsa_unreviewed·2022-05-14
CVE-2013-1500 [LOW] GHSA-w6m9-3g8m-hgf4: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows local users to affect confidentiality and integrity via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to weak permissions for shared memory.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2875 webkitgtk: out-of-bounds read in the SVG implementation (WSA-2015-0001)
bugzilla·2015-01-27·CVSS 5.0
CVE-2013-2875 [MEDIUM] CVE-2013-2875 webkitgtk: out-of-bounds read in the SVG implementation (WSA-2015-0001)
CVE-2013-2875 webkitgtk: out-of-bounds read in the SVG implementation (WSA-2015-0001)
Following vulnerability was discovered on the 2.4 stable series of WebKitGTK+:
CVE-2013-2875
core/rendering/svg/SVGInlineTextBox.cpp in the SVG implementation in Blink, as used in Google Chrome before 28.0.1500.71, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
External References:
http://webkitgtk.org/security/WSA-2015-0001.html
Discussion:
Created webkitgtk4 tracking bugs for this issue:
Affects: fedora-all [bug 1186276]
---
Created webkitgtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1181092]
---
Statement:
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to
Bugzilla
CVE-2013-2871 webkitgtk: use-after-free vulnerability in the handling of input (WSA-2015-0001)
bugzilla·2015-01-27·CVSS 7.5
CVE-2013-2871 [HIGH] CVE-2013-2871 webkitgtk: use-after-free vulnerability in the handling of input (WSA-2015-0001)
CVE-2013-2871 webkitgtk: use-after-free vulnerability in the handling of input (WSA-2015-0001)
Following vulnerability was discovered on the 2.4 stable series of WebKitGTK+:
CVE-2013-2871
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of input.
External References:
http://webkitgtk.org/security/WSA-2015-0001.html
Discussion:
Created webkitgtk4 tracking bugs for this issue:
Affects: fedora-all [bug 1186276]
---
Created webkitgtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1181092]
---
Statement:
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be a
Bugzilla
CVE-2013-2877 libxml2: Out-of-bounds read via a document that ends abruptly
bugzilla·2013-07-10·CVSS 5.0
CVE-2013-2877 [MEDIUM] CVE-2013-2877 libxml2: Out-of-bounds read via a document that ends abruptly
CVE-2013-2877 libxml2: Out-of-bounds read via a document that ends abruptly
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-2877 to the following vulnerability:
parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a document that ends abruptly, related to the lack of certain checks for the XML_PARSER_EOF state.
References:
[1] ftp://xmlsoft.org/libxml2/libxml2-2.9.0.tar.gz
[2] http://git.chromium.org/gitweb/?p=chromium/chromium.git;a=commit;h=e5d7f7e5dc21d3ae7be3cbb949ac4d8701e06de1
[3] http://googlechromereleases.blogspot.com/2013/07/stable-channel-update.html
[4] https://code.google.com/p/chromium/issues/detail?id=229019
Relevant upstream pa
Bugzilla
CVE-2013-1500 OpenJDK: Insecure shared memory permissions (2D, 8001034)
bugzilla·2013-06-17·CVSS 3.6
CVE-2013-1500 [LOW] CVE-2013-1500 OpenJDK: Insecure shared memory permissions (2D, 8001034)
CVE-2013-1500 OpenJDK: Insecure shared memory permissions (2D, 8001034)
It was discovered that the 2D component created shared memory segments with insecure permissions. A local attacker could use this flaw to read or write to the shared memory segment.
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
---
Acknowledgements:
Red Hat would like to thank Tim Brown for reporting this issue.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0958 https://rhn.redhat.com/errata/RHSA-2013-0958.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0957 https://rhn.redhat.com/errata/RHSA-2013-0957.html
---
OpenJDK7 upstream repo
http://advisories.mageia.org/MGASA-2013-0185.htmlhttp://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=975148http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/1111f9acb96bhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.htmlhttp://marc.info/?l=bugtraq&m=137545592101387&w=2http://rhn.redhat.com/errata/RHSA-2013-0963.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1059.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1060.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1081.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://secunia.com/advisories/54154http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21642336http://www-01.ibm.com/support/docview.wss?uid=swg21644197http://www.mandriva.com/security/advisories?name=MDVSA-2013:183http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.htmlhttp://www.securityfocus.com/bid/60627http://www.us-cert.gov/ncas/alerts/TA13-169Ahttps://access.redhat.com/errata/RHSA-2014:0414https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17221https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19663https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19726https://twitter.com/timb_machine/status/347110990124568577http://advisories.mageia.org/MGASA-2013-0185.htmlhttp://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=975148http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/1111f9acb96bhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.htmlhttp://marc.info/?l=bugtraq&m=137545592101387&w=2http://rhn.redhat.com/errata/RHSA-2013-0963.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1059.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1060.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1081.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1455.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1456.htmlhttp://secunia.com/advisories/54154http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21642336http://www-01.ibm.com/support/docview.wss?uid=swg21644197http://www.mandriva.com/security/advisories?name=MDVSA-2013:183http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.htmlhttp://www.securityfocus.com/bid/60627http://www.us-cert.gov/ncas/alerts/TA13-169Ahttps://access.redhat.com/errata/RHSA-2014:0414https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17221https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19663https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19726https://twitter.com/timb_machine/status/347110990124568577
2013-06-18
Published