cbcvebase.
CVE-2013-2472
published 2013-06-18

CVE-2013-2472: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45…

PriorityP269critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
22.99%
97.5th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ShortBandedRaster size checks" in 2D.

Affected

16 ranges
VendorProductVersion rangeFixed in
oraclejdk<= 1.7.0
oraclejdk<= 1.6.0
oraclejdk<= 1.5.0
oraclejdk
oraclejdk
oraclejdk
oraclejre<= 1.7.0
oraclejre<= 1.6.0
oraclejre<= 1.5.0
oraclejre
oraclejre
oraclejre
sunjdk
sunjdk
sunjre
sunjre

Detection & IOCsextracted from sources · hover to see the quote

urlhttp://packetstormsecurity.com/files/123263/
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/28331.tgz
  • Detect exploitation attempts targeting ShortComponentRaster.verify() by monitoring Java processes spawning unexpected child processes (e.g., calc.exe) — indicative of sandbox escape via numDataElements=0 boundary check bypass.
  • Monitor for untrusted Java applets or applications invoking ShortBandedRaster with mismatched data buffer sizes relative to raster attributes, which may indicate CVE-2013-2472 sandbox bypass attempts.
  • User interaction is required; monitor for drive-by download scenarios where users visit malicious pages or open malicious files that trigger Java applet execution.
  • ·Vulnerability affects Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, 5.0 Update 45 and earlier, and OpenJDK 7; exploitation requires the target to be running one of these unpatched versions.
  • ·The exploit specifically requires numDataElements to be 0 to bypass dataOffsets[] boundary checks; detections should account for this specific precondition.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu3.6LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.