The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to execute arbitrary code via vectors related to AWT, as demonstrated by Ben Murphy during a Pwn2Own competition at CanSecWest 2013. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to invocation of the system class loader by the sun.awt.datatransfer.ClassLoaderObjectInputStream class, which allows remote attackers to bypass Java sandbox restrictions.
References
Link Providers
http://blog.fuseyism.com/index.php/2013/04/22/security-icedtea-2-3-9-for-openjdk-7-released/ cve-icon cve-icon
http://blog.fuseyism.com/index.php/2013/04/25/security-icedtea-1-11-11-1-12-5-for-openjdk-6-released/ cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03898880 cve-icon cve-icon
http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Pwn2Own-2013/ba-p/5981157 cve-icon cve-icon
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/31c782610044 cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00007.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00013.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-updates/2013-05/msg00017.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-updates/2013-06/msg00099.html cve-icon cve-icon
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022796.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=137283787217316&w=2 cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0752.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0757.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0758.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-1455.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-1456.html cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-201406-32.xml cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2013:145 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2013:161 cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/javacpuapr2013-1928497.html cve-icon cve-icon
http://www.ubuntu.com/usn/USN-1806-1 cve-icon cve-icon
http://www.us-cert.gov/ncas/alerts/TA13-107A cve-icon cve-icon
http://www.zdnet.com/pwn2own-down-go-all-the-browsers-7000012283/ cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=920245 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2013-0401 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16297 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19463 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19641 cve-icon cve-icon
https://twitter.com/thezdi/status/309784608508100608 cve-icon cve-icon
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0124 cve-icon cve-icon
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0130 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2013-0401 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published: 2013-03-08T18:00:00

Updated: 2024-08-06T14:25:09.984Z

Reserved: 2012-12-07T00:00:00

Link: CVE-2013-0401

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2013-03-08T18:55:01.553

Modified: 2024-11-21T01:47:27.957

Link: CVE-2013-0401

cve-icon Redhat

Severity : Critical

Publid Date: 2013-04-16T00:00:00Z

Links: CVE-2013-0401 - Bugzilla