CVE-2013-2449
published 2013-06-18CVE-2013-2449: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to…
PriorityP427medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
3.76%
88.8th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Libraries. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to GnomeFileTypeDetector and a missing check for read permissions for a path.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | jdk | <= 1.7.0 | — |
| oracle | jdk | — | — |
| oracle | jre | <= 1.7.0 | — |
| oracle | jre | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2013-07-23·CVSS 3.6
CVE-2013-1500 [LOW] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 6.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2013-1500, CVE-2013-2454,
CVE-2013-2458)
A vulnerability was discovered in the OpenJDK Javadoc related to data
integrity. (CVE-2013-1571)
A vulnerability was discovered in the OpenJDK JRE related to information
disclosure and availability. An attacker could exploit this to cause a
denial of service or expose sensitive data over the network.
(CVE-2013-2407)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An attacker could exploit these to expose sensitive
data o
Ubuntu
OpenJDK 7 vulnerabilities
vendor_ubuntu·2013-07-16·CVSS 3.6
CVE-2013-1500 [LOW] OpenJDK 7 vulnerabilities
Title: OpenJDK 7 vulnerabilities
Summary: Several security issues were fixed in OpenJDK 7.
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2013-1500, CVE-2013-2454,
CVE-2013-2458)
A vulnerability was discovered in the OpenJDK Javadoc related to data
integrity. (CVE-2013-1571)
A vulnerability was discovered in the OpenJDK JRE related to information
disclosure and availability. An attacker could exploit this to cause a
denial of service or expose sensitive data over the network.
(CVE-2013-2407)
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An attacker could exploit these to expose sensitive
data o
Ubuntu
IcedTea Web update
vendor_ubuntu·2013-07-16·CVSS 3.6
CVE-2013-1500 [LOW] IcedTea Web update
Title: IcedTea Web update
Summary: IcedTea Web updated to work with new OpenJDK 7.
USN-1907-1 fixed vulnerabilities in OpenJDK 7. Due to upstream changes,
IcedTea Web needed an update to work with the new OpenJDK 7.
Original advisory details:
Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2013-1500, CVE-2013-2454,
CVE-2013-2458)
A vulnerability was discovered in the OpenJDK Javadoc related to data
integrity. (CVE-2013-1571)
A vulnerability was discovered in the OpenJDK JRE related to information
disclosure and availability. An attacker could exploit this to cause a
denial of service or expose sensitive data over the network.
(CVE-2013-2407)
Red Hat
OpenJDK: GnomeFileTypeDetector path access check (Libraries, 8004288)
vendor_redhat·2013-06-18·CVSS 4.3
CVE-2013-2449 [MEDIUM] OpenJDK: GnomeFileTypeDetector path access check (Libraries, 8004288)
OpenJDK: GnomeFileTypeDetector path access check (Libraries, 8004288)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Libraries. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to GnomeFileTypeDetector and a missing check for read permissions for a path.
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-ibm (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.5.0-ibm (Red Hat Enterprise Linux 6) - Not affected
Packag
GHSA
GHSA-6hpx-2f6c-q7xg: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote atta
ghsa_unreviewed·2022-05-17
CVE-2013-2449 [MEDIUM] GHSA-6hpx-2f6c-q7xg: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote atta
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality via unknown vectors related to Libraries. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to GnomeFileTypeDetector and a missing check for read permissions for a path.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4232 libtiff (tiff2pdf): use-after-free in t2p_readwrite_pdf_image()
bugzilla·2013-08-12·CVSS 6.8
CVE-2013-4232 [MEDIUM] CVE-2013-4232 libtiff (tiff2pdf): use-after-free in t2p_readwrite_pdf_image()
CVE-2013-4232 libtiff (tiff2pdf): use-after-free in t2p_readwrite_pdf_image()
Pedro Ribeiro discovered a use-after-free flaw in the t2p_readwrite_pdf_image() function in tiff2pdf, a tool for converting a TIFF image to a PDF document. A remote attacker could provide a specially-crafted TIFF file that, when processed by tiff2pdf, would cause tiff2pdf to crash or, potentially, execute arbitrary code with the privileges of the user running tiff2pdf.
References:
http://www.asmail.be/msg0055359936.html
http://www.openwall.com/lists/oss-security/2013/08/08/6
Discussion:
Upstream bug: http://bugzilla.maptools.org/show_bug.cgi?id=2449
Proposed patch: http://bugzilla.maptools.org/attachment.cgi?id=513&action=diff
---
This issue affects the version of libtiff as shipped with Red Hat Enterprise
Bugzilla
CVE-2013-2449 OpenJDK: GnomeFileTypeDetector path access check (Libraries, 8004288)
bugzilla·2013-06-17·CVSS 4.3
CVE-2013-2449 [MEDIUM] CVE-2013-2449 OpenJDK: GnomeFileTypeDetector path access check (Libraries, 8004288)
CVE-2013-2449 OpenJDK: GnomeFileTypeDetector path access check (Libraries, 8004288)
It was discovered that the GnomeFileTypeDetector did not check for read permissions. An untrusted Java application or applet could possibly use this flaw to disclose potentially sensitive information.
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0958 https://rhn.redhat.com/errata/RHSA-2013-0958.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0957 https://rhn.redhat.com/errata/RHSA-2013-0957.html
---
OpenJDK7 upstream repositories commit:
http://hg.openjdk.java.net/jdk7u/jdk7u-d
http://advisories.mageia.org/MGASA-2013-0185.htmlhttp://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/b1a2b9ac9714http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.htmlhttp://marc.info/?l=bugtraq&m=137545505800971&w=2http://rhn.redhat.com/errata/RHSA-2013-0963.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1060.htmlhttp://secunia.com/advisories/54154http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21642336http://www.mandriva.com/security/advisories?name=MDVSA-2013:183http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.htmlhttp://www.us-cert.gov/ncas/alerts/TA13-169Ahttps://bugzilla.redhat.com/show_bug.cgi?id=975145https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17192https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18717http://advisories.mageia.org/MGASA-2013-0185.htmlhttp://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/b1a2b9ac9714http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.htmlhttp://marc.info/?l=bugtraq&m=137545505800971&w=2http://rhn.redhat.com/errata/RHSA-2013-0963.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1060.htmlhttp://secunia.com/advisories/54154http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www-01.ibm.com/support/docview.wss?uid=swg21642336http://www.mandriva.com/security/advisories?name=MDVSA-2013:183http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.htmlhttp://www.us-cert.gov/ncas/alerts/TA13-169Ahttps://bugzilla.redhat.com/show_bug.cgi?id=975145https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17192https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18717
2013-06-18
Published